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1. Counterfeiting Money by The Jolly Roger 


Before reading this article, it would be a very good idea to get a book on photo 
offset 

printing, for this is the method used in counterfeiting US currency. If you are 
familiar with 

this method of printing, counterfeiting should be a simple task for you. 


Genuine currency is made by a process called "gravure", which involves etching a 
metal 

block. Since etching a metal block is impossible to do by hand, photo offset pri 
nting comes 

into the process. 


Photo offset printing starts by making negatives of the currency with a camera, 
and putting 
the negatives on a piece of masking material (usually orange in color). The stri 
pped 
negatives, commonly called "flats", are then exposed to a lithographic plate wit 
h an arc light 

plate maker. The burned plates are then developed with the proper developing che 
mical. One 

at a time, these plates are wrapped around the plate cylinder of the press. 


The press to use should be an 11 by 14 offset, such as the AB Dick 360. Make 2 n 
egatives of 

the portrait side of the bill, and 1 of the back side. After developing them and 
letting them 

dry, take them to a light table. Using opaque on one of the portrait sides, touc 

h out all the 

green, which is the seal and the serial numbers. The back side does not require 
any 

retouching, because it is a 


one color. Now, make sure a of the negatives are registered (lined up correctl 
y) on the 

flats. By the way, every time you need another serial number, shoot 1 negative o 
f the 

portrait side, cut out the serial number, and remove the old serial number from 


the flat 
replacing it with the new one. 


Now you have all 3 flats, and each represents a different color: black, and 2 sh 
ades of 

green (the two shades of green are created by mixing inks). Now you are ready to 
burn the 

plates. Take a lithographic plate and etch three marks on it. These marks must b 
e 2 and 
9/16 inches apart, starting on one of the short edges. Do the same thing to 2 mo 
re plates. 
Then, take 1 of the flats and place it on the plate, exactly lining the short ed 
ge up with the 
edge of the plate. Burn it, move it up to the next mark, and cover up the expose 
d area you 

have already burned. Burn that, and do the same thing 2 more times, moving the f 
lat up one 

more mark. Do the same process with the other 2 flats (each on a separate plate) 
. Develop 

all three plates. You should now have 4 images on each plate with an equal space 
between 

each bill. 


The paper you will need will not match exactly, but it will do for most situatio 
ns. The paper 

to use should have a 25% rag content. By the way, Disaperf computer paper (invis 
ible 

perforation) does the job well. Take the paper and load it into the press. Be su 
re to set the 


air, buckle, and paper thickness right. Start with the black plate (the plate wi 
thout the 

serial numbers). Wrap it around the cylinder and load black ink in. Make sure yo 
u run more 
than you need because there will be a lot of rejects. Then, while that is printi 
ng, mix the 

inks for the serial numbers and the back side. You will need to add some white a 


nd maybe 

yellow to the serial number ink. You also need to add black to the back side. Ex 
periment 

until you get it right. Now, clean the press and print the other side. You will 


now have a bill 

with no green seal or serial numbers. Print a few with one serial number, make a 
nother and 
repeat. Keep doing this until you have as many different numbers as you want. Th 
en cut the 

bills to the exact size with a paper cutter. You should have printed a large amo 
unt of money 
by now, but there is still one problem; the paper is pure white. To dye it, mix 
the following in 

a pan: 2 cups of hot water, 4 tea bags, and about 16 to 20 drops of green food c 
oloring 
(experiment with this). Dip one of the bills in and compare it to a genuine US b 
ill. Make the 
necessary adjustments, and dye all the bills. Also, it is a good idea to make th 
em look used. 

For example, wrinkle them, rub coffee grinds on them, etc. 


As before mentioned, unless you are familiar with photo offset printing, most of 
the 
information in this article will be fairly hard to understand. Along with gettin 
g a book on 
photo offset printing, try to see the movie "To Live and Die in LA". It is about 
a 
counterfeiter, and the producer does a pretty good job of showing how to counter 
feit. A 
good book on the subject is "The Poor Man's James Bond". 


If all of this seems too complicated to you, there is one other method available 
for 

counterfeiting: The Canon color laser copier. The Canon can replicate ANYTHING i 

n vibrant 

color, including US currency. But, once again, the main problem in counterfeitin 
g is the 

paper used. So, experiment, and good luck! 


2. Credit Card Fraud by The Jolly Roger 


For most of you out there, money is hard to come by. Until now: 


With the recent advent of plastic money (credit cards), it is easy to use someon 
e else's 

credit card to order the items you have always desired in life. The stakes are h 
igh, but the 

payoff is worth it. 


Step One: Getting the credit card information 


First off, you must obtain the crucial item: someone's credit card number. The b 
est way to 

get credit card numbers is to take the blue carbons used in a credit card transa 
ction at 

your local department store. These can usually be found in the garbage can next 

to the 

register, or for the more daring, in the garbage dumpster behind the store. But, 
due to the 

large amount of credit card fraud, many stores have opted to use a carbonless tr 
ansaction 
sheet, making things much more difficult. This is where your phone comes in hand 
y. 


First, look up someone in the phone book, and obtain as much information as poss 
ible about 

them. Then, during business hours, call in a very convincing voice - "Hello, thi 
s is John Doe 


from the Visa Credit Card Fraud Investigations Department. We have been informed 
that 

your credit card may have been used for fraudulent purposes, so will you please 
read off 

the numbers appearing on your Visa card for verification." Of course, use your i 

magination! 

Believe it or not, many people will fall for this ploy and give out their credit 
information. 


Now, assuming that you have your victim's credit card number, you should be able 
to 
decipher the information given. 


Step Two: Recognizing information from carbon copies 


Card example: 


[American Express] 
XXXX XXXXXX XXXXX 
MM/Y1 THRU MM/Y2 


JOE SHMOE 


Explanation: 


MM/Y1 is the date the card was issued, and MM/Y2 is the expiration date. The Ame 
rican 

Express Gold Card has numbers XXXXXX XXXXXXXX XXXXXXXX, and is covered for up 

to $5000.00, even if the card holder is broke. 


[Mastercard] 
5XXX XXXX XXXX XXXX 
XXXX AAA DD-MM-YY MM/YY 


JOE SHMOE 


Explanation: 


XXXX in the second row may be asked for during the ordering process. The first d 
ate is 

when the card was new, and the second is when the card expires. The most frequen 
t number 

combination used is 5424 1800 XXXX XXXX. There are many of these cards in circul 
ation, 

but many of these are on wanted lists, so check these first. 


[Visa] 
AXXX XXX(X) XXX (X) XXX (X) 
MM/YY MM/YY*VISA 


JOE SHMOE 


Explanation: 


Visa is the most abundant card, and is accepted almost everywhere. The "*VISA" i 
S 
sometimes replaced with "BWG", or followed with a special code. These codes are 
as 

follows: 


[1] MM/YY*VISA V - Preferred Card 
[2] MM/YY*VISA CV - Classic Card 


[3] MM/YY*VISA PV - Premier Card 


Preferred Cards are backed with money, and are much safer to use. Classic Cards 


are newer, 
harder to reproduce cards with decent 
ith 
Preferred coverage. Common numbers ar 
d 


backing. Premier Cards are Classic Cards w 


e 4448 020 XXX XXX, 4254 5123 6000 XXXX, an 


4254 5123 8500 XXXX. Any 4712 1250 XXXX XXXX cards are IBM Credit Union cards, 


and are risky to use, although they a 


Step Three: Testing credit 


You should now have a Visa, Mastercar 
with the 

victim's address, zip code, and phone 
etting the 


re usually covered for large purchases. 


d, or American Express credit card number, 


number. By the way, if you have problems g 


address, most phone companies offer the Address Tracking Service, which is a spe 


cia 
number you call that will give you an 


address from a 


phone number, at a nominal charge. Now you need to check the balance of credit o 


n the 


credit card (to make sure you don't run out of money), and you must also make su 


re that the 


card isn't stolen. To do this you must obtain a phone number that businesses use 


to check 
out credit cards during purchases. If 
shier when 

someone makes a credit card purchase. 
ive the 


you go to a department store, watch the ca 


He/she will usually call a phone number, g 


credit information, and then give what is called a "Merchant Number". These numb 


ers are 

usually written down on or around the 
numbers and 

copy them, or to wait until they call 
the 8 digit 
( 
h 
n 


e account 


you if it 

is OK, and will give you an authoriza 
umber down, 

and repeat it back to them to check i 
rves no real 

purpose. However, once you do this, t 
O 

b 


ld them, 
ecause the card was supposedly used 
the 


register. It is easy to either find these 


one in. Watch what they dial and wait for 


usually) merchant number. Once you call the number, in a calm voice, read off t 


umber, merchant number, amount, and expiration date. The credit bureau will tel 


tion number. Pretend you are writing this n 
t. Ignore this number completely, for it se 


he bank removes dollars equal to what you t 


to make a purchase. Sometimes you can trick 


operator by telling her the customer changed his mind and decided not to charge 
it. Of 
course, some will not allow this. Remember at all times that you are supposed to 
be a store 

clerk calling to check out the card for a purchase. Act like you are talking wit 
h a customer 

when he/she "cancels". 


Step Four: The drop 


Once the cards are cleared, you must find a place to have the package sent. NEVE 
R use a 
drop more than once. The following are typical drop sites: 


[1] An empty house 


An empty house makes an excellent place to send things. Send the package UPS, an 
d leave a 

note on the door saying, "UPS. I work days, 8 to 6. Could you please leave the p 
ackage on 

the back door step?" You can find dozens of houses from a real estate agent by t 
elling them 


you want to look around for a house. Ask for a list of twenty houses for sale, a 
nd tell them 
you will check out the area. Do so, until you find one that suits your needs. 


[2] Rent A Spot 


U-Haul sometimes rents spaces where you can have packages sent and signed for. E 
nd your 
space when the package arrives. 


[3] People's houses 


Find someone you do not know, and have the package sent there. Call ahead saying 
that "I 

called the store and they sent the package to the wrong address. It was already 
sent, but 
can you keep it there for me?" This is a very reliable way if you keep calm when 
talking to 

the people. 


Do NOT try post office boxes. Most of the time, UPS will not deliver to a post o 
ffice box, 

and many people have been caught in the past attempting to use a post office box 
. Also, 

when you have determined a drop site, keep an eye on it for suspicious character 
s and cars 

that have not been there before. 


Step Five: Making the transaction 


You should now have a reliable credit card number with all the necessary billing 
information, 
and a good drop site. 


The best place to order from is catalogues, and mail order houses. It is in your 
best 

interest to place the phone call from a pay phone, especially if it is a 1-800 n 
umber. Now, 

when you call, don't try to disguise your voice, thinking you will trick the sal 
esperson into 

believing you are an adult. These folks are trained to detect this, so your best 
bet is to 

order in your own voice. They will ask for the following: name, name as it appea 


rs on card, 

phone number, billing address, expiration date, method of shipping, and product. 
Ask if they 

offer UPS Red shipping (next day arrival), because it gives them less time to re 
search an 

order. If you are using American Express, you might have a bit of a problem ship 
ping to an 

address other than the billing address. Also, if the salesperson starts to ask q 
uestions, do 
NOT hang up. Simply talk your way out of the situation, so you won't encourage 
investigation on the order. 


If everything goes right, you should have the product, free of charge. Insurance 
picks up 
the tab, and no one is any wiser. Be careful, and try not to order anything over 
$500. In 

some states, UPS requires a signature for anything over $200, not to mention tha 
t anything 

over $200 is defined as grand theft, as well as credit fraud. Get caught doing t 
his, and you 
will bite it for a couple of years. Good luck! 


3. Making Plastic Explosives from Bleach by The Jolly Roger 


Potassium chlorate is an extremely volatile explosive compound, and has been use 
d in the 
past as the main explosive filler in grenades, land mines, and mortar rounds by 
such 
countries as France and Germany. Common household bleach contains a small amount 
of 
potassium chlorate, which can be extracted by the procedure that follows. 


First off, you must obtain: 


A heat source (hot plate, stove, etc.) 
A hydrometer, or battery hydrometer 


A large Pyrex, or enameled steel container (to weigh chemicals) 


Potassium chloride(sold as a salt substitute at health and nutrition stores) 


Take one gallon of bleach, place it in the container, and begin heating it. Whil 
e this solution 

heats, weigh out 63 grams of potassium chloride and add this to the bleach being 
heated. 

Constantly check the solution being heated with the hydrometer, and boil until y 
ou get a 

reading of 1.3. If using a battery hydrometer, boil until you read a FULL charge 


Take the solution and allow it to cool in a refrigerator until it is between roo 
m temperature 
and 0gC. Filter out the crystals that have formed and save them. Boil this solut 
ion again and 

cool as before. Filter and save the crystals. 


Take the crystals that have been saved, and mix them with distilled water in the 
following 

proportions: 56 grams per 100 milliliters distilled water. Heat this solution un 
til it boils and 

allow to cool. Filter the solution and save the crystals that form upon cooling. 
This process 
f purification is called "fractional crystallization". These crystals should be 


of 
relatively pure 
potassium chlorate. 


Powder these to the consistency of face powder, and heat gently to drive off all 
moisture. 


Now, melt five parts Vaseline with five parts wax. Dissolve this in white gasoli 
ne (camp 
stove gasoline), and pour this liquid on 90 parts potassium chlorate (the powder 
ed crystals 
from above) into a plastic bowl. Knead this liquid into the potassium chlorate u 
ntil intimately 

mixed. Allow all gasoline to evaporate. 


Finally, place this explosive into a cool, dry place. Avoid friction, sulfur, su 
lfides, and 
phosphorous compounds. This explosive is best molded to the desired shape and de 
nsity of 
1.3 grams in a cube and dipped in wax until water proof. These block type charge 
s guarantee 
the highest detonation velocity. Also, a blasting cap of at least a 3 grade must 
be used. 


The presence of the afore mentioned compounds (sulfur, sulfides, etc.) results i 
n mixtures 

that are or can become highly sensitive and will possibly decompose explosively 
while in 
storage. You should never store homemade explosives, and you must use EXTREME ca 
ution 
at all times while performing the processes in this 


article. 


You may obtain a catalog of other subject of this nature by writing: 


Information Publishing Co. 
Box 10042 


Odessa, Texas 79762 


4. Picking Master Locks by The Jolly Roger 


Have you ever tried to impress someone by picking one of those Master combinatio 
n locks 
and failed? 


The Master lock company made their older combination locks with a protection sch 
eme. If 

you pull the handle too hard, the knob will not turn. That was their biggest mis 
take. 


The first number: 


Get out any of the Master locks so you know what is going on. While pulling on t 
he clasp 

(part that springs open when you get the combination right), turn the knob to th 
e left until 

it will not move any more, and add five to the number you reach. You now have th 
e first 

number of the combination. 


The second number: 


Spin the dial around a couple of times, then go to the first number you got. Tur 
n the dial to 
the right, bypassing the first number once. When you have bypassed the first num 
ber, start 
pulling on the clasp and turning the knob. The knob will eventually fall into th 
e groove and 
lock. While in the groove, pull the clasp and turn the knob. If the knob is loos 
e, go to the 

next groove, if the knob is stiff, you have the second number of the combination 


The third number: 


After getting the second number, spin the dial, then enter the two numbers. Slow 
ly spin the 

dial to the right, and at each number, pull on the clasp. The lock will eventual 
ly open if you 

did the process right. 


This method of opening Master locks only works on older models. Someone informed 
Master 
of their mistake, and they employed a new mechanism that is foolproof (for now). 


5. The Arts of Lockpicking I by The Jolly Roger 


Lockpicking I: Cars and assorted other locks 


While the basic themes of lockpicking and uninvited entry have not changed much 
in the last 
few years, some modern devices and techniques have appeared on the scene. 


Automobiles: 


Many older automobiles can still be opened with a Slim Jim type of opener (these 
and other 
auto locksmithing techniques are covered fully in the book "In the Still of the 
Night", by 

John Russell III); however, many car manufacturers have built cases over the loc 
k 
mechanism, or have moved the lock mechanism so the Slim Jim will not work. So: 


American Locksmith Service 
P.O. Box 26 


Culver City, CA 90230 


ALS offers a new and improved Slim Jim that is 30 inches long and 3/4 inches wid 
e, so it 

will both reach and slip through the new car lock covers (inside the door). Pric 
e is $5.75 plus 
$2.00 postage and handling. 


Cars manufactured by General Motors have always been a bane to people who needed 
to 
open them, because the sidebar locking unit they employ is very difficult to pic 
k. To further 

complicate matters, the new GM cars employ metal shields to make the use of a Sl 
im Jim 
type instrument very difficult. So: 


Lock Technology Corporation 
685 Main St. 


New Rochelle, NY 10801 


LTC offers a cute little tool which will easily remove the lock cylinder without 
harm to the 
vehicle, and will allow you to enter and/or start the vehicle. The GMC-40 sells 


for $56.00 
plus $2.00 for postage and handling. 


The best general automobile opening kit is probably a set of lockout tools offer 
ed by: 


Steck MFG Corporation 
1319 W. Stewart St. 


Dayton, OH 45408 


For $29.95 one can purchase a complete set of six carbon lockout tools that will 
open more 
than 95% of all the cars around. 


Kwickset locks have become quite popular as one step security locks for many typ 
es of 

buildings. They are a bit harder to pick and offer a higher degree of security t 
han a normal 
builder installed door lock. So: 


A MFG 
1151 Wallace St. 


Massilon, OH 44646 


Price is $11.95. Kwickset locks can handily be disassembled and the door opened 
without 
harm to either the lock or the door by using the above mentioned Kwick Out tool. 


If you are too lazy to pick auto locks: 


Veehof Supply 
Box 361 


Storm Lake, IO 50588 


VS sells tryout keys for most cars (tryout keys are used since there is no one m 
aster key 

for any one make of car, but there are group type masters (a.k.a. tryout keys). 
Prices 

average about $20.00 a set. 


Updated Lockpicking: 


For years, there have been a number of pick attack procedures for most pin and t 
umbler 
lock systems. In reverse order of ease they are as follows: 


Normal Picking: 


Using a pick set to align the pins, one by one, until the shear line is set and 
the lock opens. 


Racking: 


This method uses picks that are constructed with a series of bumps, or diamond s 
hape 
notches. These picks are "raked" (i.e. run over all the pins at one time). With 
luck, the pins 

will raise in the open position and stay there. Raking, if successful, can be mu 
ch less of an 

effort than standard picking. 


Lock Aid Gun: 


This gun shaped device was invented a number of years ago and has found applicat 
ion with 
many locksmiths and security personnel. Basically, a needle shaped pick is inser 
ted in the 
snout of the "gun", and the "trigger" is pulled. This action snaps the pick up a 
nd down 
strongly. If the tip is slipped under the pins, they will also be snapped up and 
down strongly. 
With a bit of luck they will strike each other and separate at the shear line fo 
ra split 
second. When this happens the lock will open. The lock aid gun is not 100% succe 
ssful, but 
when it does work, the results are very dramatic. You can sometimes open the loc 
k with one 
snap of the trigger. 


Vibrator: 


Some crafty people have mounted a needle pick into an electric toothbrush power 
unit. This 
vibrating effect will sometimes open pin tumbler locks -- instantly. 


There is now another method to open pin and wafer locks in a very short time. Al 
though it 

resembles a toothbrush pick in appearance, it is actually an electronic device. 
I am speaking 

of the Cobra pick that is designed and sold by: 


Fed Corporation 


PeO 


Box 569 


Scottsdale, AR 85252 


The Cobra uses two nine volt batteries, teflon bearings (for less noise), and a 
cam roller. It 
comes with three picks (for different types of locks) and works both in America 


and 


overseas, on pin or wafer locks. The Cobra will open group one locks (common doo 


r locks) in 


three to seven seconds with no damage, in the hands of an experienced locksmith. 


It can 


take 


a few seconds more or up to a half a minute for someone with no experience 


at all. It 

will also open group two locks (including government, high security, and medicos 
), although 

this can take a short time longer. It will not open GM sidebar locks, although a 
device is 

about to be introduced to fill that gap. How much for this toy that will open mo 


st locks in 
seven seconds? 


$235.00 plus $4.00 shipping and handling. 


For you hard core safe crackers, FC also sells the MI-6 that will open most safe 


s at 


a cost 


of $10,000 for the three wheel attack model, and $10,500 for the four wheel mode 


Liss AE 


comes in a sturdy aluminum carrying case with monitor, disk drive and software. 


If none of these safe and sane ideas appeal to you, you can always fall back on 
the magic 
thermal lance... 


The thermal lance is a rather crude instrument constructed from 3/8 inch hollow 
magnesium rods. Each tube comes in a 10 foot length, but can be cut down if desi 


red. Each 

one is threaded on one end. To use the lance, you screw the tube together with a 
matted 

regulator (like a welding outfit uses) and hook up an oxygen tank. Then oxygen i 


s turned on 

and the rod is lit with a standard welding igniter. The device produces an incre 
dible amount 

of heat. It is used for cutting up concrete blocks or even rocks. An active lanc 
e will go 


through a foot of steel in a few seconds. The lance is also known as a burning b 
ar, and is 
available from: 


C.O.L. MFG 


7748 W. Addison 


Chicago, IL 60634 


6. The Arts of Lockpicking II by The Jolly Roger 


So you want to be a criminal. Well, if you want to be like James Bond and open a 
lock in 

fifteen seconds, then go to Hollywood, because that is the only place you are ev 
er going to 

do it. Even experienced locksmiths can spend five to ten minutes on a lock if th 
ey are 
unlucky. If you are wanting extremely quick access, look elsewhere. The followin 
g 

instructions will pertain mostly to the "lock in knob" type lock, since it is th 
e easiest to pick. 


= 


First of all, you need a pick set. If you know a locksmith, get him to make you 
a set. This will 
be the best possible set for you to use. If you find a locksmith unwilling to su 
pply a set, 

don't give up hope. It is possible to make your own, if you have access to a gri 
nder (you can 

use a file, but it takes forever). 


The thing you need is an allen wrench set (very small). These should be small en 
ough to fit 

into the keyhole slot. Now, bend the long end of the allen wrench at a slight an 
gle (not 90g). 


Now, take your pick to a grinder or a file, and smooth the end until it is round 
ed so it won't 
hang inside the lock. Test your tool out on doorknobs at your house to see if it 
will slide in 
and out smoothly. Now, this is where the screwdriver comes in. It must be small 
enough 
for it and your pick to be used in the same lock at the same time, one above the 
other. In 

the coming instructions, please refer to this chart of the interior of a lock: 


| | | | \ Y [I] Upper tumbler pin 


^^ / H [^] Lower tumbler pin 


““ “°° \ 0 [-] Cylinder wall 
/ L (This is a greatly simplified 


\ E drawing) 


The object is to press the pin up so that the space between the upper pin and th 
e lower pin 

is level with the cylinder wall. Now, if you push a pin up, it's tendency is to 
fa back down, 

right? That is where the screwdriver comes in. Insert the screwdriver into the s 
lot and 

turn. This tension will keep the "solved" pins from falling back down. Now, work 
from the 

back of the lock to the front, and when you are through, there will be a click, 
the 

screwdriver will turn freely, and the door will open. 


Do not get discouraged on your first try! It will probably take you about twenty 


to thirty 


minutes your first time. After that, you will quickly improve with practice. 


7. Solidox Bombs by The Jolly Roger 


Most people are not aware that a volatile, extremely explosive chemical can be b 


ought over 


the counter: Solidox. 


Solidox comes in an aluminum can containing 6 grey sticks, and can be bought at 


K-Mart, and 


various hardware supply shops for around $7.00. Solidox is used in welding appli 


cations as an 


oxidizing agent for the hot flame needed to melt metal. The most active ingredie 


nt in 


Solidox is potassium chlorate, a filler used in many military applications in th 


e WWII era. 


Since Solidox is 


iterally what the name says: SOLID OXygen, you must have an en 


ergy 


source for an explosion. The most common and readily available energy source is 


common. 


household sugar, or sucrose. In theory, glucose would be the purest energy sourc 


e, but it is 


hard to find a solid supply of glucose. 


Making the mixture: 


Open the can of Solidox, and remove all 6 sticks. One by one, grind up each of t 
he sticks 
(preferably with a mortar and pestle) into the finest powder possible. 


The ratio for mixing the sugar with the Solidox is 1:1, so weigh the Solidox pow 
der, and 
grind up the equivalent amount of sugar. 


Mix equivalent amounts of Solidox powder, and sugar in a 1:1 ratio. 


It is just that simple! You now have an extremely powerful substance that can be 
used in a 

variety of applications. A word of caution: be EXTREMELY careful in the entire p 
rocess. 

Avoid friction, heat, and flame. A few years back, a teenager I knew blew 4 fing 
ers off 

while trying to make a pipe bomb with Solidox. You have been warned! 


8. High Tech Revenge: The Beigebox - Rev.2 by The Jolly Roger 


I. Introduction 


Have you ever wanted a lineman's handset? Surely every phreak has at least once 
considered the phun that he could have with one. After searching unlocked phone 
company 
trucks for months, we had an idea. We could build one. We did, and named it the 
"Beige 

Box" simply because that is the color of ours. 


The beigebox is simply a consumer lineman's handset, which is a phone that can b 
e attached 
to the outside of a person's house. To fabricate a beigebox, follow along. 


II. Construction and Use 


The construction is very simple. First you must understand the concept of the de 

vice. Ina 

modular jack, there are four wires. These are red, green, yellow, and black. For 
a single line 

telephone, however, only two matter: the red (ring) and green (tip). The yellow 
and the black 

are not necessary for this project. A lineman's handset has two clips on it: the 
ring and the 


ip. Take a modular jack and look at the bottom of it's casing. There should be 
grey jack 
with four wires (red, green, yellow & black) leading out of it. To the end of th 
e red wire 
attach a red alligator clip. To the end of the green wire attach a green alligat 
or clip. The 
yellow and black wires can be removed, although I would only set them aside so t 
hat you can 
use the modular jack in future projects. Now insert your telephone's modular plu 
g into the 
modular jack. That's it. This particular model is nice because it is can be easi 
ly made, is 
inexpensive, uses common parts that are readily available, is small, is lightwei 
ght, and does 

not require the destruction of a phone. 


v ct 


III. Beige Box Uses 


There are many uses for a Beige Box. However, before you can use it, you must kn 
ow how to 

attach it to the output device. This device can be of any of Bell switching appa 
ratus that 

include germinal sets (i.e. remote switching centers, bridgin heads, cans, etc.) 
To open most 

Bell Telephone switching apparatus, you must have a 7/16 inch hex driver (or ag 
ood pair of 

needle nose pliers work also). This piece of equipment can be picked up at your 

local 
hardware store. With your hex driver (or pliers), turn the security bolt(s) appr 
oximately 


1/8 of an inch counter-clockwise and open. If your output device is locked, then 
you must 

have some knowledge of destroying and/or picking locks. However, we have never 
encountered a locked output device. Once you have opened your output device, you 
should 

see a mass of wires connected to terminals. On most output devices, the terminal 
s should be 

abeled "T" (Tip -- if not labeled, it is usually on the left) and "R" (Ring -- 

if not labeled, 

usually on the right). 


Remember: Ring - red - right. The "Three R's" -- a simple way to remember which 
is which. 
Now you must attach all the red alligator clip (Ring) to the "R" (Ring) terminal 


. Attach the 
green alligator clip (Tip) to the "T" (Tip) terminal. 


Note: If instead of a dial tone you hear nothing, adjust the alligator clips so 
that they are 
not touching each other terminals. Also make sure they are firmly attached. By t 
his time 

you should hear a dial tone. Dial ANI to find out the number you are using (you 
wouldn't 

want to use your own). Here are some practical applications: 


Eavesdropping 

Long distance, static free, free fone calls to phriends 
Dialing direct to Alliance Teleconferencing (also no static) 
Phucking people over 
Bothering the operator at little risk to yourself 
Blue Boxing with greatly reduced chance of getting caught 

Anything at all you want, since you are on an extension of that line 


Eavesdropping 


To be most effective, first attach the Beige Box then your phone. This eliminate 
s the static 

caused by connecting the box, therefore reducing the potential suspicion of your 
victim. 

When eavesdropping, it is always best to be neither seen nor heard. If you hear 
someone 
dialing out, do not panic; but rather hang up, wait, and pick up the receiver ag 
ain. The person 
will either have hung up or tried to complete their call again. If the latter is 
true, then 
listen in, and perhaps you will find information worthy of blackmail! If you wou 
d like to know 

who you are listening to, after dialing ANI, pull a CN/A on the number. 


Dialing Long Distance 


This section is self explanatory, but don't forget to dial a "1" before the NPA. 


Dialing Direct to Alliance Teleconferencing 


Simply dial 0-700-456-1000 and you will get instructions from there. I prefer th 
is method 
over PBX's, since PBX's often have poor reception and are more difficult to come 


by. 


Phucking People Over 


This 


is a very large 


ed, you can 
create a large phone 
it wi 


l be a big 


hass] 


le for them). In 


you can leave 
your phone off the hook, and they will n 
s can be 
extremely nasty because no one would expect the cause of the problem. 


topic of discussion. 


bill for the person 


addition, since you 


Just by using the other topics describ 
(they will not have to pay for it, but 
are an extension of the person's line, 


ot be able to make or receive calls. Thi 


Bothering the Operator 


This is also self explanatory and can provide hours of entertainment. Simply ask 
her things 
that are offensive or you would not like traced to your line. This also correspo 
nds to the 

previously described section, Phucking People Over. After all, guess who's line 
it gets traced 

to? 


Blue Boxing 


See a file on Blue Boxing for more details. This is an especially nice feature i 
f you live in an 
ESS-equipped prefix, since the calls are, once again, not traced to your line... 


IV. POTENTIAL RISKS OF BEIGE BOXING 


Overuse of the Beige Box may cause suspicions within the Gestapo, and result in 
legal 
problems. Therefor, I would recommend you: 


Choose a secluded spot to do your Beige Boxing, 

Use more than one output device 

Keep a low profile (i.e., do not post under your real name on a public BBS conce 
rning your 

accomplishments) 


In order to make sure the enemy has not been inside your output device, I recomm 
end you 

place a piece of transparent tape over the opening of your output device. Theref 
or, if it is 

opened in your absence, the tape will be displaced and you will be aware of the 
fact that 

someone has intruded on your territory. 


Now, imagine the possibilities: a $2000 dollar phone bill for that special perso 
n, 976 
numbers galore, even harassing the operator at no risk to you! Think of it as wa 
lking into an 

enemies house, and using their phone to your heart's content. 


9. How to make a COy bomb by the Jolly Roger 


You will have to use up the cartridge first by either shooting it or whatever. W 
ith a nail, 

force a hole bigger so as to allow the powder and wick to fit in easily. Fill th 
e cartridge with 
black powder and pack it in there real good by tapping the bottom of the cartrid 


ge ona 
hard surface (I said TAP not SLAM!). Insert a fuse. I recommend a good water-pro 
of 


cannon fuse, or an m-80 type fuse, 


but firecracker fuses work, if you can run like a black man runs from the cops a 
fter raping a 
white girl.) Now, light it and run like hell! It does wonders for a row of mailb 
oxes (like the 

ones in apartment complexes), a car (place under the gas tank), a picture window 


window sill), a phone booth (place right under the phone), or any other devious 
place. This 
thing throws shrapnel, and can make quit a mess!! 


10. Thermite II by Jolly Roger 
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to get some 
ron-oxide (which is RUST! 
rt time: 


Get a DC converter like 


Thermite is nasty shit. Here is a good and easy way to make it. The first step i 


). Here is a good way to make large quantities in a sh 


ate the 


wires, and strip them both. 


Now you need a jar of wa 
SALT!) 


Now insert both wires in 


in...) 


nd let them sit for five 
other. 


his is the POSITIVE(+) wire. If you do not do this test right, the final produc 


will be 
he opposite (chemically) 
ere 
although it IS useful!). 


ter with 


added to it. This makes the water conductive. 
to the mixture (I am assuming you plugged the converter 


minutes. 


the one used on a train set. Cut the connector off, sepa 


a tablespoon or so of sodium chloride (which is 


One of them will start bubbling more than the 


of rust, which is RUST ACID. You have no use for this 


Anyway, put the nail tied to the positive wire into the jar. Now put the negativ 


wire in 


he other end. Now let it sit overnight and in the morning scrape the rust off o 


the nail 


& repeat until you got a bunch of rust on the bottom of the glass. Be generous w 
ith your 


ust collection. If you are going through the trouble of making thermite, you mi 
ht as 
ell make a lot, right? 
Now remove the excess water and pour the crusty solution onto a cookie sheet. Dr 
it in 
he sun for a few hours, or inside overnight. It should be an orange-brown color 
although I have seen it in many different colors! Sometimes the color gets fuck 
d up, 
hat can I say... but it is still iron oxide!) 
Crush the rust into a fine powder and heat it in a cast-iron pot until it is red 
. Now mix 
he pure iron oxide with pure aluminum filings which can be bought or filed down 
by 
and from an aluminum tube or bar. The ratio or iron oxide to aluminum is 8 gram 
to 3 
rams. 


Congrats! You have just made THERMITE! Now, to light it... 
Thermite requires a LOT of heat 
agnesium ribbon (which is sort of hard to find.. call around) will do the trick 


It takes 


tick the 


it burn 


hone cash boxes. 


(more than a blow torch!) to ignite. However, 


he heat from the burning magnesium to light the thermite. 
Now when you see your victim's car, pour a fifty-cent sized pile onto his hood, 


ibbon in it, and light the ribbon with the blow torch. Now chuckle as you watch 


hrough the hood, the block, the axle, and the pavement. BE CAREFUL! The ideal 
ixtures can vaporize CARBON STEEL! Another idea is to use thermite to get into 


11. Touch Explosives by the Jolly Roger 


This is sort of a mild explosive, but it can be quite dangerous in large quantit 
ies. To make 

touch explosive (such as that found in a snap-n-pop, but more powerful), use thi 
s recipe: 


Mix iodine crystals into ammonia until the iodine crystals will not dissolve int 
o the 

ammonia anymore. Pour off the excess ammonia and dry out the crystals on a bakin 

g 
sheet the same way as you dried the thermite (in other words, just let it sit ov 
ernight!). 

Be careful now because these crystals are now your touch explosive. Carefully wr 
ap a 
bunch in paper (I mean carefully! Friction sets 'em off!) and throw them around. 
. pretty 

loud, huh? They are fun to put on someone's chair. Add a small fish sinker to th 
em and 
they can be thrown a long distance (good for crowds, football games, concerts, e 
tC.) 


12. Letter Bombs by The Jolly Roger 


You wi first have to make a mild version of thermite. Use my recipe, but subst 

itute 

iron fillings for rust. 

Mix the iron with aluminum fillings in a ratio of 75% aluminum to 25% iron. This 
mixture 

will burn violently in a closed space (such as an envelope). This bring us to ou 

r next 
ingredient... 

Go to the post office and buy an insulated (padded) envelope. You know, the type 
that is 

double layered. Separate the layers and place the mild thermite in the main sect 
ion, 

where the letter would go. Then place magnesium powder in the outer layer. There 
is 

your bomb! ! 

Now to light it... this is the tricky part and hard to explain. Just keep experi 

menting 


until you get something that works. The fuse is just that touch explosive I have 
told you 
about in another one of my anarchy files. You might want to wrap it like a long 
cigarette 


and then place it at the top of the envelope in the outer layer (on top of the p 
owdered 

magnesium). When the touch explosive is torn or even squeezed hard it will ignit 
e the 
powdered magnesium (sort of a flash light) and then it will burn the mild thermi 


te. If 

the thermite didn't blow up, it would at least burn the fuck out of your enemy ( 
it does 

wonders on human flesh!). 


13. Paint Bombs by The Jolly Roger 


To make a pain bomb you simply need a metal pain can with a refastenable lid, a 
nice bright 
color paint (green, pink, purple, or some gross color is perfect!), and a quanti 
ty of dry ice. 

Place the paint in the can and then drop the dry ice in. Quickly place the top o 
n and then run 

ike hell! With some testing you can time this to a science. It depends on the r 


ice to paint to the size of the can to how full it is. If you are really pissed 
off at someone, 
you could place it on their doorstep, knock on the door, and then run!! Paint wi 
fly all over 

the place!! 


14. Ways to send a car to Hell by The Jolly Roger 


There are 1001 ways to destroy a car but I am going to cover only the ones that 
are the 

most fun (for you), the most destructive (for them), and the hardest to trace (f 
or the 

cops). 


Place thermite on the hood, light it, and watch it burn all the way through the 
pavement! 
Tape a COy bomb to the hood, axle, gas tank, wheel, muffler, etc. 
Put a tampon, dirt, sugar (this one is good!), a ping pong ball, or just about 
nything that 
will dissolve in the gas tank. 
Put potatoes, rocks, bananas, or anything that will fit, into the tailpipe. Use 
a broom 
handle to stuff 'em up into the tailpipe. 

Put a long rag into the gas tank and light it... 

Steal a key, copy it, replace it, and then steal the stereo. 

Break into the car. Cut a thin metal ruler into a shape like this: 


Slide it into the outside window and keep pulling it back up until you catch the 

lock cable 

which should unlock the door. This device is also called a SLIM JIM. Now get the 
stereo, 

equalizer, radar detector, etc. Now destroy the inside. (A sharp knife does wond 
ers on the 

seats!) 


15. Do you hate school? by The Jolly Roger 


One of my favorites for getting out of a class or two is to call in a bomb threa 
t. Tell ‘em 

that it is in a locker. Then they have to check them all, whilst you can slip aw 
ay for an 

hour or two. You can even place a fake bomb (in any locker but YOURS!). They mig 
ht 
cancel school for a week while they investigate (of course, you will probably ha 
ve to 

make it up in the summer). 

Get some pure potassium or pure sodium, put it in a capsule, and flush it down t 
he toilet 
(smells awful! Stinks up the whole school!). 
Use a smoke grenade in the hallway. 


Steal the computer passwords & keys. Or steal the 80 column cards inside if they 
are 
(gag) IBM. 
Make friends with student assistants and have them change your grades when the 
teachers hand in their bubble sheets for the report cards. 

Spit your gum out on the carpet in the library or whatever and grind it into the 
carpet. 
Watch the janitors cry! 
Draw on lockers or spraypaint on the building that the principal is a fascist. 
Stick a potato in the tailpipe of the principal's car. 
USE YOUR IMAGINATION! 


16. Phone related vandalism by the Jolly Roger 


If you live where there are underground lines then you will be able to ruin some 
one's phone 
life very easily. All you must do is go to their house and find the green juncti 
on box that 


interfaces their line (and possibly some others in the neighborhood) with the ma 
jor lines. 

These can be found just about anywhere but they are usually underneath the neare 
st phone 


pole. Take a socket wrench and loosen the nut on the right. Then just take clipp 
ers or a 
sledge hammer or a bomb and destroy the insides and pull up their phone cable. N 
ow cut it 
into segments so it can't be fixed but must be replaced (There is a week's worth 
of work 

for 'em!!) 


17. Highway radar jamming by The Jolly Roger 


Most drivers wanting to make better time on the open road will invest in one of 
those 


expensive radar detectors. However, this device will not work against a gun type 
radar unit 

in which the radar signal is not present until the cop has your car in his sight 
s and pulls the 
trigger. Then it is TOO LATE for you to slow down. A better method is to continu 
ously jam 
any signal with a radar signal of your own. I have tested this idea with the coo 
peration of a 

local cop and found that his unit reads random numbers when my car approached hi 
m. It is 


suprisingly easy to make a low power radar transmitter. A nifty little semicondu 

ctor called a 

Gunn Diode will generate microwaves when supplied with the 5 to 10 volt DC ande 

nclosed in 

the correct size cavity (resonator). An 8 to 3 terminal regulator can be used to 
get this 

voltage from a car's 12v system. However, the correct construction and tuning of 
the cavity 


is difficult without good microwave measurement equipment. Police radars commonl 


operate on the K band at 22 GHz. Or more often on the X band at 10«25 GHz. most 
microwave intruder alarms and motion detectors (mounted over automatic doors in 
supermarkets & banks, etc.) contain a Gunn type transmitter/receiver combination 
that 
transmits about 10 kilowatts at 10«25 GHz. These units work perfectly as jammers 
If you 


cannot get one locally, write to Microwave Associates in Burlington, Massachuset 
ts and ask 

them for info on 'Gunnplexers' for ham radio use. When you get the unit it may b 
e mounted 

in a plastic box on the dash or in a weather-proof enclosure behind the PLASTIC 

grille. 

Switch on the power when on an open highway. The unit will not jam radar to the 

side or 

behind the car so don't go speeding past the radar trap. An interesting phenomen 
a you will 

notice is that the drivers who are in front of you who are using detectors will 

hit their 

brakes as you approach large metal signs and bridges. Your signal is bouncing of 
f of these 

objects and triggering their radar detectors! 


PS If you are interested in this sort of thing, get a copy of POPULAR COMMUNICAT 
IONS. 

The ads in there tell you where you can get all kinds of info on all kinds of ne 
at equipment 

for all kinds of neat things! 


18. Smoke Bombs by the Jolly Roger 


Here is the recipe for one hell of a smoke bomb! 


4 parts sugar 


6 parts potassium nitrate (Salt Peter) 


Heat this mixture over a LOW flame until it melts, stirring well. Pour it into a 
future 
container and, before it solidifies, imbed a few matches into the mixture to use 
as fuses. 
One pound of this stuff will fill up a whole block with thick, white smoke! 


19. Mail Box Bombs by the Jolly Roger 


Two liter bottle of chlorine (must contain sodium hypochlorate) 


Small amount of sugar 


Small amount of water 


Mix all three of these in equal amounts to fill about 1/10 of the bottle. Screw 
on the lid and 

place in a mailbox. It's hard to believe that such a small explosion will litera 
lly rip the 

mailbox in half and send it 20 feet into the air! Be careful doing this, though, 
because if 

you are caught, it is not up to the person whose mailbox you blew up to press ch 
arges. It is 

up to the city. 


= 


20. The easiest way to hot-wire cars by the Jolly Roger 


Get in the car. Look under the dash. If it's enclosed, forget it unless you want 
to cut 

through it. If you do, do it near the ignition. Once you get behind or near the 
ignition look 

for two red wires. In older cars red was the standard color, if not, look for tw 
o matched 

pairs. When you find them, cross them and take off! 


21. How to make Napalm by the Jolly Roger 


[| Pour some gas into an old bowl, or some kind of container. 

Get some styrofoam and put it in the gas, until the gas won't eat anymore. You s 
hould 

have a sticky syrup. 

Put it on the end of something (don't touch it!!). The unused stuff lasts a long 
time! 


22. How to make a fertilizer bomb by The Jolly Roger 


Ingredients: 


Newspaper 

Fertilizer (the chemical kind, GREEN THUMB or ORCHO) 
Cotton 
Diesel fuel 


Make a pouch out of the newspaper and put some fertilizer in it. Then put cotton 
on top. 

Soak the cotton with fuel. Then light and run like you have never ran before! Th 
is blows up 

500 square feet so don't do it in an alley!! 


23. Tennis Ball Bombs by The Jolly Roger 


Ingredients: 


Strike anywhere matches 
A tennis ball 

A nice sharp knife 

Duct tape 


Break a ton of matchheads off. Then cut a SMALL hole in the tennis ball. Stuff a 
1l of the 

matchheads into the ball, until you can't fit any more in. Then tape over it wit 
h duct tape. 
Make sure it is real nice and tight! Then, when you see a geek walking down the 
street, give 
it a good throw. He will have a blast!! 


24. Diskette Bombs by The Jolly Roger 


You need: 


A disk 

Scissors 

White or blue kitchen matches (they MUST be these colors!) 
Clear nail polish 


Carefully open up the diskette (3«" disks are best for this!) 


Remove the cotton covering from the inside. 


Scrape a lot of match powder into a bowl 


k the 


matchpowder!) 


After 


you have a lot, spread it evenly on the disk. 


Using the nail polish, spread it over the match mixture 


Let it dry 


Careful] 


on the inside 
(where it came apart). 


(use a wooden scraper, metal might spar 


ly put the diskette back together and use the nail polish to seal it shut 


When that disk is in a drive, the drive head attempts to read the disk, which ca 
uses a small 
(ENOUGH HEAT TO MELT THE DISK DRIVE AND FUCK THE HEAD UP!!). Let the 
fuckhead try and fix THAT!!! 


fire 


25. Unlisted Phone Numbers by The Jolly Roger 


There are a couple of different ways of doing this. Let's see if this one will h 


ing 


e 
h 
rs. These 
o 
l 


lp: Every city 
as one or more offices dedicated to assigning numbers to the telephone wire pai 


ffices are called DPAC offices and are available to service reps who are instal 


or 


repairing phones. To get the DPAC number, a service rep wou 


SCTV 


ce 


number for billing information in the town that the number 
is trying to 


get the unlisted number of. 


ld call the customer 


is located in that he 


(Got that?) The conversation would go something like 


this: "Hi, 
Amarillo, this is Joe from Anytown business office, I need the DPAC number for t 
he south 

side of town." This info is usually passed out with no problems, so... if the fi 


rst person you 
call doesn't have it, try another. REMEMBER, no one has ANY 


üu are 


Nave, 


when you are talking on the phone, so you can be anyone you 
en you call 

the DPAC number, just tell them that you need a listing for 
hat you 


or the name. DPAC DOES NOT SHOW WHETHER THE NUMBER IS 


IDEA who the hell yo 
damn well please! Wh 


either the address t 


LISTED OR 


UNLISTED!! Also, if you're going to make a habit of chasing 


numbers down, you mi 


ght want 

to check into getting a criss-cross directory, which lists phone numbers by thei 
r addresses. 

It costs a couple hundred bucks, but it is well worth it if you have to chase mo 
re than one 

or two numbers down! 


26. Fuses by The Jolly Roger 


You would be surprised how many files are out there that use what falls under th 
e category 

of a "fuse." They assume that you just have a few lying around, or know where to 
get them. 

Well, in some parts of the country, fuses are extremely hard to come by... so th 
is file tells 

you how to make your own. Both fuses presented here are fairly simple to make, a 
nd are 

fairly reliable. 


SLOW BURNING FUSE - 2 inches per minute 


Materials needed: 


[| Cotton string or 3 shoelaces 
Potassium Nitrate or Potassium Chlorate 
Granulated sugar 


Procedure: 


Wash the cotton string or shoelaces in HOT soapy water, then rinse with fresh wa 
ter 


Mix the following together in a glass bowl: 


1 part potassium nitrate or potassium chlorate 
1 part granulated sugar 
2 parts hot water 


Soak strings or shoelaces in this solution 


Twist/braid 3 strands together and allow them to dry 


Check the burn rate to see how long it actually takes!! 


FAST BURNING FUSE - 40 inches per minute 


Materials needed: 


Soft cotton string 
Fine black powder (empty a few shotgun shells!) 
Shallow dish or pan 


Procedure: 


Moisten powder to form a paste. 


Twist/braid 3 strands of cotton together. 


Rub paste into string and allow to dry. 


Check the burn rate!!! 


27. How to make Potassium Nitrate by The Jolly Roger 


Potassium Nitrate is an ingredient in making fuses, among other things. Here is 
how you 
make it: 


Materials needed: 


3« gallons of nitrate bearing earth or other material 
« cup of wood ashes 
Bucket or other similar container about 4-5 gallons in volume 

2 pieces of finely woven cloth, each a bit bigger than the bottom of the bucket 
Shallow dish or pan at least as large in diameter as the bucket 

Shallow, heat resistant container 

2 gallons of water 

Something to punch holes in the bottom of the bucket 

1 gallon of any type of alcohol 

A heat source 

Paper & tape 


Procedure: 


Punch holes on the inside bottom of the bucket, so that the metal is "puckered" 
outward 
from the bottom. 


Spread cloth over the holes from the bottom. 


Place wood ashes on the cloth. Spread it out so that it covers the entire cloth 
and has about 
the same thickness. 


Place 2nd cloth on top of the wood ashes. 


Place the dirt or other material in the bucket. 


Place the bucket over the shallow container. NOTE: It may need support on the bo 
ttom so 
that the holes on the bottom are not blocked. 


Boil water and pour it over the earth very slowly. Do NOT pour it all at once, a 
s this will clog 
the filter on the bottom. 


Allow water to run through holes into the shallow dish on the bottom. 


Be sure that the water goes through ALL of the earth! 


Allow water in dish to cool for an hour or so. 


Carefully drain the liquid in the dish away, and discard the sludge in the botto 
m. 


Boil this liquid over a fire for at least two hours. Small grains of salt will f 
orm - scoop these 
out with the paper as they form. 


When the liquid has boiled down to « its original volume let it sit. 


After « hour, add equal volume of the alcohol; when this mixture is poured throu 


gh paper, 
small white crystals appear. This is the potassium nitrate. 


Purification: 


Redissolve crystals in small amount of boiling water. 


Remove any crystals that appear. 


Pour through improvised filter then heat concentrated solution to dryness. 


Spread out crystals and allow to dry. 


28. Exploding Lightbulbs by The Jolly Roger 


Materials needed: 


Lightbulb (100w) 

Socket (duh...) 

= cup soap chips 

Blackpowder! (open some shotgun shells!) 
7 cup kerosene or gasoline 

Adhesive tape 

Lighter or small blowtorch 

Glue 


Procedure for a simple exploding lightbulb: 


Drill a small hole in the top of the bulb near the threads! 


Carefully pour the blackpowder into the hole. Use enough so that it touches the 
filament! 


Insert into socket as normal (make sure the light is off or else YOU will be the 
victim! !) 


Get the hell out!! 


Procedure for a Napalm Bulb: 


Heat kerosene/gasoline in a double boiler. 


Melt soap chips, stirring slowly. 


Put somewhere and allow to cool. 


Heat the threads of the bulb VERY carefully to melt the glue. Remove threads, sl 
owly 

drawing out the filament. Do NOT break the cheap electrical igniters and/or the 
filament or this won't work!! 


Pour the liquid into the bulb, and slowly lower the filament back down into the 
bulb. Make 
sure the filament is dipped into the fluid. 


Re-glue the threads back on. Insert it into a socket frequently used by the vict 
im and get 
the hell out!! 


When the victim flips the switch, he will be in for a BIG surprise! 


29. Under water igniters by The Jolly Roger 


Materials needed: 


Pack of 10 silicon diodes. (Available at Radio Shack. You will know you got the 
right ones 

if they are very, very small glass objects!) 

Pack of matches 

1 candle 


Procedure: 


Light the candle and allow a pool of molten wax to form in the top. 


Take a single match and hold the glass part of a single diode against the head. 
Bend the 
diode pins around the matchhead so that one wraps in an upward direction and the 
n 
sticks out to the side. Do the same with the other wire, but in a downward direc 
tion. 
The diodes should now be hugging the matchhead, but its wires MUST NOT TOUCH 


EACH OTHER! 


Dip the matchhead in wax to give it a water-proof coat. These work underwater 


Repeat to make as many as you want. 


How to use them: 


When these little dudes are hooked across a 6v battery, the diode reaches what i 


s called 
breakdown 
lly 


voltage. When most electrical components reach this voltage, they usua 


produce great amounts of heat and light, while quickly melting into a little blo 


b. This h 


enough to ignite a matchhead. Thes 


st 


other ign 


eat is 


iters refuse to work. 


are recommended for use underwater, where mo 


30. Home-brew blast cannon by The Jolly Roger 


Materials needed: 


plastic drain pipe, 3 feet long, at least 3 « inches in diameter. 
smaller plastic pipe, about 6 inches long, 2 inches in diameter. 
large lighter, with fluid refills (this gobbles it up!) 

pipe cap to fit the large pipe, 1 pipe cap to fit the small pipe. 
feet of bellwire. 

1 SPST rocker switch. 

16v polaroid pot-a-pulse battery. 

15v relay (get this at Radio Shack). 

Electrical Tape. 

One free afternoon. 


Procedure: 


Cut the bell wire into three equal pieces, and strip the ends. 


Cut a hole in the side of the large pipe, the same diameter as the small pipe. T 
hread the 

hole and one end of the small pipe. They should screw together easily. 

Take a piece of scrap metal, and bend it into an "L" shape, then attach it to th 
e level on 

the lighter: 


/ gas switch is here 


!lighter!!<---metal lever!! 


Now, every time you pull the 'trigger' gas should flow freely from the lighter. 
You may 

need to enlarge the 'gas port' on your lighter, if you wish to be able to fire m 
ore 

rapidly. 

Connect two wires to the two posts on the switch. 

Cut two holes in the side of the smaller tube, one for the switch on the bottom, 
and one 
for the metal piece on the top. Then, mount the switch in the bottom, running th 


e wires 

up and out of the top. 

Mount the lighter/trigger in the top. Now the switch should rock easily, and the 
trigger 
should cause the lighter to pour out gas. Re-screw the smaller tube into the lar 
ger one, 
hold down the trigger a bit, let it go, and throw a match in there. If all goes 
well, you 
should hear a nice big 'THUD!' 

Get a hold of the relay, and take off the top. 


v/ 


2 /<--the center object is the metal finger inside the relay 


cc / 


(elo) 4 


Connect (1) to one of the wires coming from the switch. Connect (2) to (4), and 
connect 

(5) to one side of the battery. Connect the remaining wire from the switch to th 

e other 

side of the battery. Now you should be able to get the relay to make a little 'b 
uzzing' 

sound when you flip the switch and you should see some tiny little sparks. 

Now, carefully mount the relay on the inside of the large pipe, towards the back 
Screw 
on the smaller pipe, tape the battery to the side of the cannon barrel (yes, but 
looks 
aren't everything!) 

You should now be able to let a little gas into the barrel and set it off by fli 
pping the 

switch. 

Put the cap on the back end of the large pipe VERY SECURELY. You are now ready f 


or 
the first trial-run! 


To Test: 


Put something very, very large into the barrel, just so that it fits 'just right 
'. Now, finda 
strong guy (the recoil will probably knock you on your ass if you aren't careful 
!). Put ona 

shoulderpad, earmuffs, and possibly some other protective clothing (trust the Jo 
lly Roger! 

You are going to need it!). Hold the 


trigger down for 30 seconds, hold on tight, and hit the switch. With luck and th 


e proper 


adjustments, you should be able to put a frozen orange through 7 or plywood at 2 


5 feet. 


31. Chemical Equivalency list by The Jolly Roger 


RCAC Taes alice sate i eters cate Mea col aati eee Acetate Lobe bie A aOU led E E E Suerte dans Gum Arabic 
ACGEVC ACT Mra. nu ews Oona teehee aa ow eee EET E ee eas wee EE Vinegar 
ALUMINUM OAR E 6.254% caus Seed Bie Wack acre Bae Rete Aa a hn GS Ate Dee Se Vn SS ee Alumia 
Aluminum: Potassium Sulphate rroa r skis hae oes Behe se ease RNA Soa BE RES SS Alum 
AVUMINUM:, SUTLATC CS sese bora. cee naene eaae aga ang. Saw rdyd lace ee, Oana ewe aw la emia o. a a er’ Alum 
Ammonium Carnate eripiet rra tee Ee alee Be CEE ee OER LES oe LN ore ee Lee ele lens Hartshorn 
Ammonium: AVAT OI Ee e da wtice Mase E ene aoe ae dhlantewd eee alee ea E Et Ammonia 
Ammonium Nitrates A Hod watts. aie ee widal eh Olean alee wee ethets aR ep NEE Salt Peter 


Ammonium OLGA Ciwcck. iaa dees das Ad Se ee he ba Ree eee ee eb ee ee ae ds Ammonia Soap 


AmyltaGStat @nvdetetise aod eae aie ate ee CERNE E Ree eee ees Banana Oil 


Bar rum Sulit etek Soe se ae Sg a sO ee eae ok eles Se Black Ash 
Carbon:CarbinatCie.c0% agi E eae ees ees eee See hie om He belces 5 Chalk 
Carbonterrachlorrde..< ews dienes ¢ bowen aad diate ed ened Mewes aenet sh Cleaning Fluid 
Caleium HypOChlOride.<scci acto. ERFAREN dete Cee es Peewee Bleaching Powder 
Ca terum ORDIS siegte tick Saige ua a E 40 Soot sien Gold 6 toed: bac ote de sioner e E boo Lime 
Caleium: Sulfate soip iat wad Oo ete eee aie ae ba alee Gene Plaster of Paris 
Carbonic ACLs ss rnei Gas EENE Vak oe eee tua ete E ¥ Band weed Yee ee A Seltzer 
Cet yltrimethylammOnTUMO Lomi dense i cide Siew ee a eer ae ON a los eee Oe a ce Ammonium Salt 
BER VInedt eh VOR TEI ps5 0 eid ia a ates al awa ee whee ale ed eit Tete ioe ta ete ale we ea Oe i Dutch Fluid 
REE ETCH OKT Ce aot itn eae E Sn Rig ha OI te eee a he te ied a Iron Rust 
PUrEUP AACN VOC. eo .2c604 eae eo eee bee Reed seeks eS Se eee ee ES Bran Oil 
GLU OO SS ee) sobre 2 apa leds ap e bares ie ld a lag nee, aya ar dere le ea, a bbcode lana eee, acevo vend Corn Syrup 
GLAPNDEG ecco oe ea Gite aee 24 Gate Se Pee ES ae ae eas Pencil Lead 
Hydrochloric ACid.4di50% ataeied da gaat a A E ARA ete E ela Muriatic Acid 
Hydrogen: Peroxide sireeni beens oot awa the Uh etwas dike Peroxide 
Lead AGS TAT Sanwa cena teed ae E eral than eter tace sate fot E T ahah tl aca E se baie ah es Sugar of Lead 
Lead: TEL OAOKPIS ves inte niere r uue do poten seca bee ids PE ete E OEA E E E See tad Seas Red Lead 
Magnesium SIli Cates on’ ar eo ut ect tae ewe teats et ba ented ee ee a Talc 


Magnesium Sulfatess +. oid ds ade ss aida ba seeded ei wetd Sek ek eee is Epsom Salt 


Méethylsalicy latex ks acts ONTE OARE EREA eek eae d Sia as Winter Green Oil 


Naphthalene r cts Sage eects a acai ey be GaN Al a cs OS NS, AEU E EEE abc ATE bd wd aces Mothballs 
PHENOL fn ed Mites sa wah bts scaled bee e eds bes es dewalt bee oa N Carbolic Acid 
Potassium Bicarbonate. occ cee. bee eee Rees eee ee eee Cream of Tarter 
Potassium Chromium. Sulfate... cece pees eee SERGE Pew eee bee Chromealum 
POEASS LUM NIGTACCL Ss 4.24 unini 24 tease r DAE dane Meanie Gut shew eg Saw Salt Peter 
Sodium :OX10E feted Peat aay Oi date Sens OA eels ME ie ade heels Shee a Sand 
Sodium BiCarbonated-n. ta ndenedies bata cubed tea eke ev GA ee ee Baking Soda 
Sodium Borats Sew see Ea EE eaten E edate lee aw T TEE ee ere te BU EE a a sre eek SN « Borax 
SOdMUM: “CarbOnat Cc rw EEEE LSE ta a owe wae ee eee ee eee eas Washing Soda 
SOCWMIMCCH TORUS aa obs Siew gk oot eee Gee ie hd N Biotest SAE Salt 
Sodiwm HY OLOXTAG alee ow kd Mea A ECEN Sle Wa ei eens ere Ais eta oe es eee oe Lye 
Sodium- SITVCATE Ss eeri renos mirne Dae KEE Shae Gwe So She ce gw deere oS eee Glass 
Sodium SUITAtE. cose eee ere ee Gavia ee eee oe eRe ee adele ae ee oes Glauber's Salt 
Sodium: THIGSULEGt Gs 22nd chek ce ieee wu e ka eae eee CA aa ee ees Photographer's Hypo 
Sulfuric AGT es an ood wht etek ah OOS ee a FO Oe ee athe CA eee a nde bbe Battery Acid 
SUCSTOS So sete hie Bia ee ete EE tke tated ae E ee ate atl uate E ahh ast E alae, Bole ahaha tees Cane Sugar 
ZINC ‘CHVORUEAS Hose atte tend Meta ito teed in ea Sate E Se E ed ee MS Tinner's Fluid 
ZING: SULLA we 6 whee bee eo RANE Kak SO WOE tee ees Ua eee eae White Vitriol 


32. Phone Taps by The Jolly Roger 


Here is some info on phone taps. In this file is a schematic for a simple wireta 
p& 

instructions for hooking up a small tape recorder control relay to the phone lin 
e. 


First, I will discuss taps a little. There are many different types of taps. The 

re are 

transmitters, wired taps, and induction taps to name a few. Wired and wireless t 

ransmitters 

must be physically connected to the line before they will do any good. Once a wi 

reless tap is 

connected to the line, it can transmit all conversations over a limited receptio 

n range. The 

phones in the house can even be modifies to pick up conversations in the room an 

d transmit 

them too! These taps are usually powered off of the phone line, but can have an 

external 

power source. You can get more information on these taps by getting an issue of 

Popular 

Communications and reading through the ads. Wired taps, on the other hand, need 

no power 

source, but a wire must be run from the line to the listener or to a transmitter 

. There are 

obvious advantages of wireless taps over wired ones. There is one type of wirele 

ss tap that 

looks like a normal telephone mike. All you have to do is replace the original m 

ike with this 

and it will transmit all conversations! There is also an exotic type of wired ta 

p known as the 

‘Infinity Transmitter' or 'Harmonica Bug'. In order to hook one of these, it mus 

t be 

installed inside the phone. When someone calls the tapped phone & *before* it ri 

ngs and 

blows a whistle over the line, the transmitter picks up the phone via a relay. T 

he mike on the 

phone is activated so that the caller can hear all of the conversations in the r 

oom. There is 

a sweep tone test at 415/BUG-1111 which can be used to detect one of these taps. 
If one of 

these is on your line & the test # sends the correct tone, you will hear a click 
Induction 

taps have one big advantage over taps that must be physically wired to the phone 

. They do 

not have to be touching the phone in order to pick up the conversation. They wor 

k on the 

same principle as the little suction-cup tape recorder mikes that you can get at 
Radio 

Shack. Induction mikes can be hooked up to a transmitter or be wired. 


Here is an example of industrial espionage using the phone: 


A salesman walks into an office & makes a phone call. He fakes the conversation, 
but when 
he hangs up he slips some foam rubber cubes into the cradle. The called party ca 
n still hear 

all conversations in the room. When someone picks up the phone, the cubes fall a 
way 
unnoticed. 


A tap can also be used on a phone to overhear what your modem is doing when you 
are war- 
dialing, hacking, or just plain calling a bbs. 


Here is the schematic: 


The 100K pot is used for volume. It should be on its highest (least resistance) 
setting if you 

hook a speaker across the output. but it should be set on its highest resistance 
for a tape 
recorder or amplifier. You may find it necessary to add another 10 - 40K. The ca 

pacitor 

should be around .47 MFD. It's only purpose is to prevent the relay in the phone 

from 

tripping & thinking that you have the phone off of the hook. the audio output tr 

ansformer is 

available at Radio Shack. (part # 273-138E for input). The red & the white wires 

go to the 

output device. You may want to experiment with the transformer for the best outp 

ut. 

Hooking up a tape recorder relay is easy. Just hook one of the phone wires (usua 

lly red) to 

the end of one of the relay & the other end just loop around. This bypasses it. 

It should 

ook like this: 


RAKAKAAKAAKAA 


RELAY^^ 


(part #275-004 from Radio Shack works fine) 


If you think that you line is tapped, the first thing to do is to physically ins 
pect the line 

yourself ESPECIALLY the phones. You can get mike replacements with bug detectors 
built 

in. However, I would not trust them too much. It is too easy to get a wrong read 


ing. 


For more info: 


BUGS AND ELECTRONIC SURVEILLANCE from Desert Publications HOW TO AVOID 
ELECTRONIC EAVESDROPPING & PRIVACY INVASION. I do not remember who this one 
is from... you might want to try Paladin Press. 


33. How to make a landmine by The Jolly Roger 


First, you need to get a push-button switch. Take the wires of it and connect on 
e to a nine 


volt battery connector and the other to a solar igniter (used for launching mode 
l rockets). A 


very thin piece of stereo wire will usually do the trick if you are desperate, b 
ut I 


recommend the igniter. Connect the other wire of the nine-volt battery to one en 
d of the 


switch. Connect a wire from the switch to the other lead on the solar igniter. 


switch battery 
\/ 

Aay 

ae 

\ / 

solar igniter 

| 

| 

| 


explosive 


Now connect the explosive (pipe bomb, m-80, COy bomb, etc.) to the igniter by at 
taching 
the fuse to the igniter (seal it with scotch tape). Now dig a hole; not too deep 
but enough to 
cover all of the materials. Think about what direction your enemy will be coming 
from and 
plant the switch, but leave the button visible (not TOO visible!). Plant the exp 
losive about 3- 
5 feet away from the switch because there will be a delay in the explosion that 
depends on 
how short your wick is, and, if a homemade wick is being used, its burning speed 
. But if you 
get it right... and your enemy is close enough......... 
BBBBBBBO00000000000000000000000OMMMM! 


34. A different kind of Molitov Cocktail by The Jolly Roger 


Here is how you do it: 


Get a coke bottle & fill it with gasoline about half full. 


Cram a piece of cloth into the neck of it nice and tight. 


Get a chlorine tablet and stuff it in there. You are going to have to force it b 
ecause the 
tablets are bigger than the opening of the bottle. 


Now find a suitable victim and wing it in their direction. When it hits the pave 
ment or any 


surface hard enough to break it, and the chlorine and gasoline mix..... BOOM! !!! 
1 


35. Phone Systems Tutorial by The Jolly Roger 


To start off, we will discuss the dialing procedures for domestic as well as int 
ernational 
dialing. We will also take a look at the telephone numbering plan. 


North American Numbering Plan 


In North America, the telephone numbering plan is as follows: 


digit Numbering Plan Area (NPA) code , i.e., area code 

digit telephone number consisting of a 3 digit Central Office (CO) code plus a 
4 digit 

station number 


3 
7 


These 10 digits are called the network address or destination code. It is in the 
format of: 


Area Code Telephone # 


N*X NXX-XXXX 


Where: N = a digit from 2 to 9 


x 


th 


X=a 


Area Co 


e digit 0 or 1 


digit from 0 to 9 


des 


Check your telephone book or the separate listing of area codes found on many bb 


s's. He 
are the 


700 


re 
special area codes (SAC'S): 
TWX (USA) 

TWX (Canada) 


New Service 


710 - 


810 - 


900 


TWX (USA) 
WATS 
TWX (USA) 


DIAL-IT Services 


TWX (USA) 


least o 


e often 


s). 


TWX (Tel 


rn 
Union. 
baud 


(last I checked! They are most likely faster now!). 


se 
machine 
h an 


ne 


The other area codes never cross state lines, therefore each state must have at 


exclusive NPA code. When a community is split by a state line, the CO numbers ar 


interchangeable (i.e., you can dial the same number from two different area code 


lex II) consists of 5 teletype-writer area codes. They are owned by Weste 


These SAC's may only be reached via other TWX machines. These run at 110 


Besides the TWX numbers, the 


s are routed to normal telephone numbers. TWX machines always respond wit 


answerback. For example, WU's FYI TWX # is (910) 279-5956. The answerback for th 


is 
service 


is "WU FYI MAWA". 


If you don't want to but a TWX machine, you can still send TWX messages using Ea 
sylink 
[800/325-4112]. However you are gonna have to hack your way onto this one! 


700: 


700 is currently used by AT&T as a call forwarding service. It is targeted towar 

ds salesmen 

on the run. To understand how this works, I'll explain it with an example. Let's 
say Joe Q. 

Salespig works for AT&T security and he is on the run chasing a phreak around th 

e country 

who royally screwed up an important COSMOS system. Let's say that Joe's 700 # is 
(700) 

382-5968. Every time Joe goes to a new hotel (or most likely SLEAZY MOTEL), he d 

ials a 

special 700 #, enters a code, and the number where he is staying. Now, if his bo 

ss received 

some important info, all he would do is dial (700) 382-5968 and it would ring wh 

erever Joe 

last programmed it to. Neat, huh? 


800: 


This SAC is one of my favorites since it allows for toll free calls. INWARD WATS 


(INWATS), or Inward Wide Area Telecommunications Service is the 800 numbers that 
we 

are all familiar with. 800 numbers are set up in service areas or bands. There a 
re 6 of 

these. Band 6 is the largest and you can call a band 6 # from anywhere in the US 
except 

the state where the call is terminated (that is why most companies have one 800 
number 

for the country and then another one for their state.) Band 5 includes the 48 co 


ntiguous 
states. All the way down to band 1 which includes only the states contiguous to 
T 


hat one. 
herefore, less people can reach a band 1 INWATS number than a band 6 number. 


Intrastate INWATS #'s (i.e., you can call it from only 1 state) always have a 2 
as the last 
digit in the exchange (i.e., 800-NX2-XXXX). The NXX on 800 numbers represent the 
area 

where the business is located. For example, a number beginning with 800-431 woul 
d 

terminate at a NY CO. 


800 numbers always end up in a hunt series in a CO. This means that it tries the 
first 

number allocated to the company for their 800 lines; if this is busy, it will tr 

y the next 

number, etc. You must have a minimum of 2 lines for each 800 number. For example 
Travelnet uses a hunt series. If you dial (800) 521-8400, it will first try the 

number 

associated with 8400; if it is busy it will go to the next available port, etc. 
INWATS 

customers are billed by the number of hours of calls made to their number. 


OUTWATS (OUTWARD WATS): OUTWATS are for making outgoing calls only. Large 
companies use OUTWATS since they receive bulk-rate discounts. Since OUTWATS 


E 


numbers cannot have incoming calls, they are in the format of: 


(800) *XXX-XXXX 


Where * is the digit 0 or 1 (or it may even be designated by a letter) which can 
not be dialed 

unless you box the call. The *XX identifies the type of service and the areas th 
at the 

company can call. 


Remember: 


INWATS + OUTWATS = WATS EXTENDER 


900: 


This DIAL-IT SAC is a nationwide dial-it service. It is use for taking televisio 
n polls and 

other stuff. The first minute currently costs an outrageous 50-85 cents and each 
additional 

minute costs 35-85 cents. He'll take in a lot of revenue this way! 


Dial (900) 555-1212 to find out what is currently on this service. 


CO CODES 


These identify the switching office where the call is to be routed. The followin 
g CO codes 
are reserved nationwide: 


555 - directory assistance 


844 time. These are now in! 


936 - weather the 976 exchange 


950 - future services 
958 - plant test 


959 - plant test 


970 - plant test (temporary) 


976 DIAL-IT services 


Also, the 3 digit ANI & ringback #'s are regarded as plant test and are thus res 
erved. 
These numbers vary from area to area. 


You cannot dial a 0 or 1 as the first digit of the exchange code (unless using a 
blue box!). 

This is due to the fact that these exchanges (000-199) contains all sorts of int 
eresting shit 

such as conference #'s, operators, test #'s, etc. 


950: 


Here are the services that are currently used by the 950 exchange: 


1000 - SPC 


1022 - MCI Execunet 


1033 - US Telephone 
1044 - Allnet 


1066 - Lexitel 


1088 - SBS Skyline 


These SCC's (Specialized Common Carriers) are free from fortress phones! Also, t 
he 950 
exchange will probably be phased out with the introduction of Equal Access. 


Plant Tests: 


These include ANI, Ringback, and other various tests. 


976: 


Dial 976-1000 to see what is currently on the service. Also, many bbs's have lis 
tings of 
these numbers. 


N11 codes: 


Bell is trying to phase out some of these, but they still exist in most areas. 


011 - international dialing prefix 
211 - coin refund operator 

411 - directory assistance 

611 - repair service 

811 - business office 


911 - EMERGENCY 


International Dialing 


With International Dialing, the world has been divided into 9 numbering zones. T 
o make an 
international call, you must first dial: International Prefix + Country code + N 
ational 
number. 


In North America, the international dialing prefix is 011 for station-to-station 
calls. If you 
can dial International numbers directly in your area then you have International 
Direct 

Distance Dialing (IDDD). 


The country code, which varies from 1 to 3 digits, always has the world numberin 
g zone as 

the first digit. For example, the country code for the United Kingdom is 44, thu 
s it is in 

world numbering zone 4. Some boards may contain a complete listing of other coun 
try codes, 
but here I give you a few: 


1 - North America (US, Canada, etc.) 
20 - Egypt 

258 - Mozambique 

34 - Spain 

49 - Germany 

52 - Mexico (southern portion) 

7 - USSR 


81 - Japan 


98 - Iran (call & hassle those bastards!) 


If you call from an area other than North America, the format is generally the s 
ame. For 
example, let's say that you wanted to call the White House from Switzerland to t 
ell the 
president that his numbered bank account is overdrawn (it happens, you know!). F 
irst you 

would dial 00 (the SWISS international dialing prefix), then 1 (the US country c 
ode), 
followed by 202-456-1414 (the 


national number for the White House. Just ask for Georgy and give him the bad ne 
ws!) 


Also, country code 87 is reserved for Maritime mobile service, i.e., calling shi 
ps: 


871 - Marisat (Atlantic) 


871 - Marisat (Pacific) 


872 - Marisat (Indian) 


International Switching: 


In North America there are currently 7 no. 4 ESS's that perform the duty of ISC 
(Inter- 

nation Switching Centers). All international calls dialed from numbering zone 1 
will be routed 
through one of these "gateway cities". They are: 


182 - White Plains, NY 


183 - New York, NY 
184 - Pittsburgh, PA 
185 - Orlando, Fl 
186 - Oakland, CA 
187 - Denver, CO 


188 - New York, NY 


The 18X series are operator routing codes for overseas access (to be further dis 
cussed 

with blue boxes). All international calls use a signaling service called CCITT. 
It is an 

international standard for signaling. 


OK.. there you go for now! If you want to read more about this, read part two wh 
ich is the 
next file #36 in the Jolly Roger's cookbook! 


36. Phone Systems Tutorial part II by The Jolly Roger 


Part II will deal with the various types of operators, office hierarchy, & switc 
hing 
equipment. 


Operators 


There are many types of operators in the network and the more common ones will b 


e 
discussed. 


TSPS Operator: 


The TSPS [(Traffic Service Position System) as opposed to This Shitty Phone Serv 
ice] 
Operator is probably the bitch (or bastard, for the female liberationists out th 
ere) that 

most of us are used to having to deal with. Here are his/her responsibilities: 


Obtaining billing information for calling card or third number calls 


Identifying called customer on person-to-person calls. 


Obtaining acceptance of charges on collect calls. 


Identifying calling numbers. This only happens when the calling number is not au 
tomatically 
recorded by CAMA (Centralized Automatic Message Accounting) & forwarded from the 


local office. This could be caused by equipment failures (ANIF- Automatic Number 


Identification Failure) or if the office is not equipped for CAMA (ONI- Operator 


Number Identification). 


I once had an equipment failure happen to me & the TSPS operator came on and sai 
d, “What 

number are you calling FROM?" Out of curiosity, I gave her the number to my CO, 

she 

thanked me & then I was connected to a conversation that appeared to be between 

a frame 

man & his wife. Then it started ringing the party I wanted to originally call & 

everyone 
phreaked out (excuse the pun). I immediately dropped this dual line conference! 


You should not mess with the TSPS operator since she KNOWS which number that you 
are 
calling from. Your number will show up on a 10-digit LED read-out (ANI board). S 
he also 
knows whether or not you are at a fortress phone & she can trace calls quite rea 
dily! Out of 

all of the operators, she is one of the MOST DANGEROUS. 


INWARD operator: 


This operator assists your local TSPS ("0") operating connecting calls. She will 
never 
uestion a call as long as the call is within HER SERVICE AREA. She can only be 
eached via 

ther operators or by a blue box. From a blue box, you would dial KP+NPA+121+ST 
or the 

NWARD operator that will help you connect any calls within that NPA only. (Blue 
Boxing 

will be discussed in a future file). 


HHO KK OQ 


DIRECTORY ASSISTANCE Operator: 


This is the operator that you are connected to when you dial: 411 or NPA-555-121 
2. She 

does not readily know where you are calling from. She does not have access to un 
listed 

numbers, but she DOES know if an unlisted # exists for a certain listing. 


There is also a directory assistance operator for deaf people who use teletypewr 


iters. If 

your modem can transfer BAUDOT [(45« baud). One modem that I know of that will d 
o this 

is the Apple Cat acoustic or the Atari 830 acoustic modem. Yea I know they are h 
ard to 

find... but if you want to do this.. look around!) then you can call him/her up 
and have an 
interesting conversation. The number is: 800-855-1155. They use the standard Tel 
ex 
abbreviations such as GA for go ahead. they tend to be nicer and will talk longe 
r than your 
regular operators. Also, they are more vulnerable into being talked out of infor 
mation 
through the process of "social engineering" as Chesire Catalyst would put it. 


Unfortunately, they do not have access to much. I once bullshitted with one of t 
hese 

operators a while back and I found out that there are 2 such DA offices that han 
dle TTY. 

One is in Philadelphia and the other is in California. They have approx. 7 opera 
tors each. 
Most of the TTY operators think that their job is 


boring (based on an official "BIOC poll"). They also feel that they are under-pa 
id. They 
actually call up a regular DA number to process your request (sorry, no fancy co 
mputers!) 


Other operators have access to their own DA by dialing KP+NPA+131+ST (MF). 


CN/A operators: 


CN/A Operators are operators that do exactly the opposite of what directory assi 

stance 

operators are for. In my experience, these operators know more than the DA op's 

do & they 

are more susceptible to "social engineering." It is possible to bullshit a CN/A 

operator for 

the NON-PUB DA number (i.e., you give them the name & they give you the unlisted 

number. 

See the article on unlisted numbers in this cookbook for more info about them.). 

This is due 
h 


e fact that they assume that you are a fellow company employee. Unfortunate 
he 
AT&T breakup has resulted in the break-up of a few NON-PUB DA numbers and policy 


changes in CN/A. 


INTERCEPT Operator: 


The intercept operator is the one that you are connected to when there are not e 
nough 

recordings available to tell you that the number has been disconnected or change 
d. She 

usually says, "What number you calling?" with a foreign accent. This is the lowe 
st operator 
lifeform. Even though they don't know where you are calling from, it is a waste 
or your time 
to try to verbally abuse them since they usually understand very little English 
anyway. 


Incidentally, a few area DO have intelligent INTERCEPT Operators. 


OTHER Operators: 


And then there are the: Mobile, Ship-to-Shore, Conference, Marine Verify, "Leave 
Word 

and Call Back", Rout & Rate (KP+800+141+1212+ST), & other special operators who 
have one 

purpose or another in the network. 


Problems with an Operator: 


Ask to speak to their supervisor... or better yet the Group Chief (who is the hi 
ghest ranking 
official in any office) who is the equivalent of the Madame in a whorehouse. 


By the way, some CO's that will allow you to dial a 0 or 1 as the 4th digit, wil 
L also allow you 

to call special operators & other fun Tel. Co. numbers without a blue box. This 
is very rare, 

though! For example, 212-121-1111 will get you a NY Inward Operator. 


Office Hierarchy 


Pa 


Every switching office in North America (the NPA system), is assigned an office 
name and 
class. There are five classes of offices numbered 1 through 5. Your CO is most 1 
ikely a class 
5 or end office. All long-distance (Toll) calls are switched by a toll office wh 
ich can be a 
class 4, 3, 2, or 1 office. There is also a class 4X office called an intermedia 
te point. The 4X 
office is a digital one that can have an unattended exchange attached to it (kno 
wn as a 
Remote Switching Unit (RSU)). 


The following chart will list the Office #, name, & how many of those office exi 
st (to the 
best of my knowledge) in North America: 


ClassNameAbbNumber ExistinglRegional CenterRC122Sectional CenterSC673Primary 
CenterPC2304Toll CenterICcl,3004PToll PointTPN/A4XIntermediate PointIPN/A5End 
OfficeEO19, OO06RSURSUN/A 


When connecting a call from one party to another, the switching equipment usuall 

y tries to 

find the shortest route between the class 5 end office of the caller & the class 

5 end 

office of the called party. If no inter-office trunks exist between the two part 

ies, it will 

then move upward to the next highest office for servicing calls (Class 4). If th 

e Class 4 

office cannot handle the call by sending it to another Class 4 or 5 office, it w 

ill then be sent 
h 
È 


to the next highest office in the hierarchy (3). The switching equipment first u 
ses the 

high-usage interoffice trunk groups, if they are busy then it goes to the final; 
trunk groups 
on the next highest level. If the call cannot be connected, you will probably ge 
t a re-order 
[120 IPM (interruptions per minute) busy signal] signal. At this time, the guys 
at Network 

Operations are probably shitting in their pants and trying to avoid the dreaded 
Network 

Dreadlock (as seen on TV!). 


It is also interesting to note that 9 connections in tandem is called ring-aroun 
d-the-rosy 
and it has never occurred in telephone history. This would cause an endless loop 
connection 

[a neat way to really screw up the network]. 


The 10 regional centers in the US & the 2 in Canada are all interconnected. they 
form the 

foundation of the entire telephone network. Since there are only 12 of them, the 

y are listed 

below: 


Class 1 Regional Office LocationNPADallas 4 ESS214Wayne, PA215Denver 4T303Regina 
No. 

2SP1-4W (Canada)306St. Louis 4T314Rockdale, GA404Pittsburgh 4E412Montreal No. 1 
4AETS (Canada)504 


37. Basic Alliance Teleconferencing by The Jolly Roger 


Introduction: 


This phile will deal with accessing, understanding and using the Alliance Teleco 
nferencing 
Systems. It has many sections and for best use should be printed out. 


> 


Lance: 


tance Teleconferencing is an independent company which allows the general pub 

LC. EO 

ccess and use it's conferencing equipment. Many rumors have been floating aroun 

that 

lance is a subsidiary of AT&T. Well, they are wrong. As stated above, Allianc 

is an 
entirely independent company. They use sophisticated equipment to allow users to 
talk to 

many people at once. 


Pap rH 


The Number: 


Alliance is in the 700 exchange, thus it is not localized, well, not in a way. A 
lliance is only in 

certain states, and only residents of these certain states can access by dialing 
direct. This, 

however, will be discussed in a later chapter. The numbers for alliance are as f 
ollows: 


0-700-456-1000 (Chicago) 
-1001 (Los Angeles) 
-1002 (Chicago) 


-1003 (Houston) 


-2000 (?) 
-2001 (?) 
-2002 (?) 
-2003 (?) 
-3000 (?) 
-3001 (?) 
-3002 (?) 
-3003 (?) 


The locations of the first 4 numbers are known and I have stated them. However, 
the 

numbers in the 200x and 300x are not definitely known. Rumor has it that the pat 
tern 

repeats itself but this has not been proven. 


Dialing: 


As stated before, Alliance is only in certain stated and only these states can a 
ccess them 
via dialing direct. However, dialing direct causes your residence to be charged 
for the 

conference and conference bills are not low!!! 


Therefore, many ways have been discovered to start a conference without having i 
t billed 
to ones house. They are as follows: 


Dialing through a PBX. 
Incorporating a Blue Box. 


Billing to a loop. 


Billing to a forwarded call. 


I am sure there are many more, but these are the four I will deal with. 


Dialing through a PBX: 


Probably the easiest method of creating a free conference is through a PBX. Simp 
y call one 

in a state that has Alliance, input the PBX's code, dial 9 for an outside line a 
nd then dial 

alliance. An example of this would be: 


PBX: 800-241-4911 


When it answers it will give you a tone. At this tone input your code. 


Code: 1234 


After this you will receive another tone, now dial 9 for an outside line. 


You will now hear a dial tone. Simply dial Alliance from this point and 


the conference will be billed to the PBX. 


Using a Blue Box: 


Another rather simple way of starting a conference is with a Blue Box. The follo 
wing 
procedure is how to box a conference: 


Dial a number to box off of. In this example we will use 609-609-6099 When the p 
arty 

answers hit 2600hz. This will cause the fone company's equipment to think that y 
ou have 

hung up. You will hear a <beep><kerchunk> You have now 'seized' a trunk. After t 
his, switch 

to multi-frequency and dial: 


KP-0-700-456-x00x-ST 


KP = KP tone on Blue Box 
X = variable between 1 and 3 
ST = ST tone on Blue Box 


The equipment now thinks that the operator has dialed Alliance from her switchbo 
ard and 
the conference shall be billed there. Since Blue Boxing is such a large topic, t 
his is as far as 

I will go into it's uses. 


Billing to a loop: 


A third method of receiving a free conference is by billing out to a loop. A loo 
p is 2 numbers 
that when two people call, they can talk to each other. You're saying woop-tee-d 
o right? 
Wrong! Loops can be <very> useful to phreaks. First, dial alliance direct. After 
going through 
the beginning procedure, which will be discussed later in this tutorial, dial 0 
and wait for an 
Alliance operator. When she answers tell her you would like to bill the conferen 
ce to such 
and such a number. (A loop where your phriend is on the other side) She will the 
n call that 


number to receive voice verification. Of course your phriend will be waiting and 
will accept 
the charges. Thus, the conference is billed to the loop. 


Billing to call forwarding: 


When you dial a number that is call forwarded, it is first answered by the origi 
nal location, 
then forwarded. The original location will hang up if 2600hz is received from on 
ly one end 
of the line. Therefore, if you were to wait after the forwarded residence answer 
ed, you 
would receive the original location's dial tone. 


Example: 


Dial 800-325-4067 


The original residence would answer, then forward the call, a second type of rin 
ging would 

be heard. When this second residence answers simply wait until they hang up. Aft 
er about 

twenty seconds you will then receive the original residence's dial tone since it 
heard 2600hz 
from one end of the line. Simply dial Alliance from this point and the conferenc 
e will be 


billed to the original residence. These are the four main ways to receive a free 
conference. 
I am sure 


many more exist, but these four are quite handy themselves. 


Logon Procedure: 


Once Alliance answers you will hear a two-tone combination. This is their way of 
saying 'How 

many people do you want on the conference dude?' Simply type in a 2-digit combin 
ation, 

depending on what bridge of Alliance you are on, between 10 and 59. After this e 
ither hit 
'*' to cancel the conference size and input another or hit '#' to continue. You 
are now in 

Alliance Teleconferencing and are only seconds away from having your own roaring 


conference going strong!!! 


Dialing in Conferees: 


To dial your first conferee, dial ltnpatpretsuff and await his/her answer. 


area code 


I 


npa 
pre = prefix 


suff = suffix 


If the number is busy, or if no one answers simply hit '*' and your call will be 
aborted. But, 

if they do answer, hit the '#' key. This will add them to the conference. Now co 

mmence 

dialing other conferees. 


Joining Your Conference: 


To join your conference from control mode simply hit the '#' key. Within a secon 
d or two 

you will be chatting with all your buddies. To go back into control mode, simply 
hit the '#' 

key again. 


Transferring Control: 


To transfer control to another conferee, go into control mode, hit the # 6+1+npa 


t+pretsuff 

of the conferee you wish to give control to. If after, you wish to abort this tr 
ansfer hit the 

'*' key. 


NOTE: Transfer of control is often not available. When you receive a message sta 
ting this, 
you simply cannot transfer control. 


Muted Conferences: 


To request a muted conference simply hit the 9 key. I am not exactly sure what a 
muted 

conference is but it is probably a way to keep unwanted eavesdroppers from liste 
ning in. 


Dialing Alliance Operators: 


Simply dial 0 as you would from any fone and wait for the operator to answer. 


Ending Your Conference: 


To end your conference all together, that is kick everyone including yourself of 
f, go into 

control mode and hit '*'...after a few seconds simply hang up. Your conference i 
s over. 


Are Alliance Operators Dangerous? 


No. Not in the least. The worst they can do to you while you are having a confer 
ence is drop 
all conferees including yourself. This is in no way harmful, just a little aggra 
vating. 


Alliance and Tracing: 


Alliance can trace, as all citizens of the United States can. But this has to al 
l be pre- 

meditated and AT&T has to be called and it's really a large hassle, therefore, i 
t is almost 

never done. Alliance simply does not want it known that teenagers are phucking t 
hem over. 

The only sort of safety equipment Alliance has on-line is a simple pen register. 

This little 

device simply records all the numbers of the conferees dialed. No big deal. All 

Alliance can 
do is call up that persons number, threaten and question. However, legally, they 
can do 
nothing because all you did was answer your fone. 


NOTE: Almost all instructions are told to the person in command by Alliance reco 
rdings. A 
lot of this tutorial is just a listing of those commands plus information gather 
ed by either 
myself or the phellow phreaks of the world!!! 


38. Aqua Box Plans by The Jolly Roger 


Every true phreaker lives in fear of the dreaded FBI 'Lock In Trace'. For a long 
time, it 

was impossible to escape from the Lock In Trace. This box does offer an escape r 
oute with 
simple directions to it. This box is quite a simple concept, and almost any phre 
aker with 

basic electronics knowledge can construct and use it. 


The Lock In Trace 


A lock in trace is a device used by the FBI to lock into the phone users locatio 
n so that he 
can not hang up while a trace is in progress. For those of you who are not famil 
iar with the 


££ 


concept of ‘locking in', then here's a brief description. The FBI can tap into a 
conversation, 

sort of like a three-way call connection. Then, when they get there, they can pl 
ug electricity 

into the phone line. All phone connections are held open by a certain voltage of 
electricity. 

That is why you sometimes get static and faint connections when you are calling 

far away, 
because the electricity has trouble keeping the line up. What the lock in trace 
does is cut 
into the line and generate that same voltage straight into the lines. That way, 

when you try 

and hang up, voltage is retained. Your phone will ring just like someone was cal 
ing you even 

after you hang up. (If you have call waiting, you should understand better about 
that, for 
call waiting intercepts the electricity and makes a tone that means someone is g 
oing through 
your line. Then, it is a matter of which voltage is higher. When you push down t 
he receiver, 
then it see-saws the electricity to the other side. When you have a person on ea 
ch line it is 

impossible to hang up unless one or both of them will hang up. If you try to han 
g up, voltage 
is retained, and your phone will ring. That should give you an understanding of 
how calling 
works. Also, when electricity passes through a certain point on your phone, the 

electricity 

causes a bell to ring, or on some newer phones an electronic ring to sound.) So, 
in order to 

liminate the trace, you somehow must lower the voltage level on your phone line 
. You should 

know that every time someone else picks up the phone line, then the voltage does 
decrease a 


O 


little. In the first steps of planning this out, Xerox suggested getting about a 
ndred 


he power out of the line so the voltage can not be kept up. Rather sudden drain 
g of power 

ould quickly short out the FBI voltage machine, because it was only built to su 
stain the 

exact voltage necessary to keep the voltage out. For now, imagine this. One of t 
he normal 
Radio Shack generators that you can go pick up that one end of the cord that hoo 
ks into the 

central box has a phone jack on it and the other has an electrical plug. This wa 
y, you can 

"flash" voltage through the line, but cannot drain it. So, some 


5 


u 

phones all hooked into the same line that could all be taken off the hook at the 
same time. 

That would greatly decrease the voltage level. That is also why most three-way c 

onnections 

that are using the bell service three way calling (which is only $3 a month) bec 

ome quite 

faint after a while. By now, you should understand the basic idea. You have to d 

rain all of 

t 

i 

ë 


modifications have to be done. 


Materials 


A BEOC (Basic Electrical Output Socket), like a sma lamp-type connection, wher 
e you just 
have a simple plug and wire that would plug into a light bulb. One of cords ment 
ioned above, 
if you can't find one then construct your own... Same voltage connection, but th 
e restrainer 
must be built in (I.E. The central box) Two phone jacks (one for the modem, one 
for if you 

are being traced to plug the aqua box into) Some creativity and easy work. 


Notice: No phones have to be destroyed/modified to make this box, so don't go ou 
t and buy 
a new phone for it! 


Procedure 


All right, this is a very simple procedure. If you have the BEOC, it could drain 
into anything: 

a radio, or whatever. The purpose of having that is you are going to suck the vo 
ltage out 

from the phone line into the electrical appliance so there would be no voltage 1 
eft to lock 

you in with. 


Take the connection cord. Examine the plug at the end. It should have only two p 


ro 


ngs. If it 


has three, still, do not fear. Make sure the electrical appliance is turned off 
unless you 

want to become a crispy critter while making this thing. Most plugs will have a 
hard 

plastic design on the top of them to prevent you from getting in at the electric 
al wires 

inside. Well, remove it. If you want to keep the plug (I don't see why...) then 
just cut 

the top off. When you look inside, Low and Behold, you will see that at the base 
of the 

prongs there are a few wires connecting in. Those wires conduct the power into t 
he 

appliance. So, you carefully unwrap those from the sides and pull them out until 
they are 

about an inch ahead of the prongs. If you don't want to keep the jack, then just 
rip the 

prongs out. If you are, cover the prongs with insulation tape so they will not c 
onnect 

with the wires when the power is being drained from the line. 


Do 
y 

co 
ve 
ot 
0) 

fu 
en 


the same thing with the prongs on the other plug, so you have the wires evenl 


nnected. Now, wrap the end of the wires around each other. If you happen to ha 
the 
her end of the voltage cord hooked into the phone, stop reading now, you're to 


cking stupid to continue. After you've wrapped the wires around each other, th 


cover the whole thing with the plugs with insulating tape. Then, if you built yo 


ur 


own 


control box or if you bought one, then 
. That box 
is your ticket out of this. 


cram all the wires into it and reclose it 


Re-check everything to make sure it's all in place. This is a pretty flimsy conn 


ection, but on 


Plug it 


later models when you get more experienced at it then you can solder away at it 
form the whole device into one big box, with some kind of cheap Mattel hand-held 


inside to be the power connector. In order to use it, just keep this box handy. 


into the jack if you want, but it will 
nnected. 


slightly lower the voltage so it isn't co 


When you plug it in, if you see sparks, unplug it and restart the whole thing. B 


ut if it 
just seems fine then leave it. 


Use 


Now, so you have the whole thing plugged in and all... Do not use this unless th 


e situation is 

desperate! When the trace has gone on, 
on the 

appliance that it was hooked to. It wi 
"s a great 

source... The voltage to keep a phone 
ht bulb should 

drain it all in and probably short the 


39. Hindenberg Bomb by The Jolly Roger 


Needed: 


Balloon 

Bottle 

Liquid Plumber 
Piece Aluminum foil 
Length Fuse 


PPrPrPPE 


don't panic, unplug your phone, and turn 


ll need energy to turn itself on, and here 


line open is pretty small and a simple lig 


FBI computer at the same time. 


Fi the bottle 3/4 full with Liquid Plumber and add a little piece of aluminum 


foil to it. Put 


the balloon over the neck of the bottle until the balloon is full of the resulti 
ng gas. This is 
highly flammable hydrogen. Now tie the balloon. Now light the fuse, and let it r 
ise. When 

the fuse contacts the balloon, watch out!!! 


40. How to Kill Someone with your Bare Hands by The Jolly Roger 


This file will explain the basics of hand-to-hand combat, and will tell of the b 
est places to 
strike and kill an enemy. When engaged in hand-to-hand combat, your life is alwa 
ys at stake. 
There is only one purpose in combat, and that is to kill your enemy. Never face 
an enemy 
with the idea of knocking him out. The chances are extremely good that he will k 
ill YOU 
instead. When a weapon is not available, one must resort to the full use of his 
natural 

weapons. The natural weapons are: 


The knife edge of your hands. 


Fingers folded at the second joint or knuckle. 


The protruding knuckle of your second finger. 


The heel of your hand. 
Your boot 

Elbows 

Knees 


Your Teeth. 


Attacking is a primary factor. A fight was never won by defensive action. Attack 
with all of 

your strength. At any point or any situation, some vulnerable point on your enem 
ies body will 
be open for attack. Do this while screaming as screaming has two purposes. 


To frighten and confuse your enemy. 


To allow you to take a deep breath which, in turn, will put more oxygen in your 
blood stream. 


Your balance and balance of your enemy are two important factors; since, if you 

succeed in 

making your enemy lose his balance, the chances are nine to one that you can kil 
l him in your 

next move. The best over-all stance is where your feet are spread about shoulder 
s width 

apart, with your right foot about a foot ahead of the left. Both arms should be 

bent at the 

elbows parallel to each other. Stand on the balls of your feet and bend your wai 
st slightly. 

Kind of like a boxer's crouch. Employing a sudden movement or a scream or yell c 
an throw 
your enemy off-balance. There are many vulnerable points of the body. We will co 
ver them 

now: 


Eyes: Use your fingers in a V-shape and attack in gouging motion. 


Nose: (Extremely vulnerable) Strike with the knife edge of the hand along the bri 
dge, which 

will cause breakage, sharp pain, temporary blindness, and if the blow is hard en 
ough, death. 

Also, deliver a blow with the heel of your hand in an upward motion, this will s 
hove the bone 

up into the brain causing death. 


Adam's Apple: This spot is usually pretty well protected, but if you get the cha 

nce, strike 

hard with the knife edge of your hand. This should sever the wind-pipe, and then 
it's all 

over in a matter of minutes. 


Temple: There is a large artery up here, and if you hit it hard enough, it will 
cause death. If 

you manage to knock your enemy down, kick him in the temple, and he'll never get 
up again. 


Back of the Neck: A rabbit punch, or blow delivered to the base of the neck can 
easily 

break it, but to be safe, it is better to use the butt of a gun or some other he 
avy blunt 

object. 


Upper lip: A large network of nerves are located. These nerves are extremely clo 
se to the 
skin. A sharp upward blow will cause extreme pain, and unconsciousness. 


Ears: Coming up from behind an enemy and cupping the hands in a clapping motion 
over the 
victims ears can kill him immediately. The vibrations caused from the clapping m 
otion will 
burst his eardrums, and cause internal bleeding in the brain. 


Groin: A VERY vulnerable spot. If left open, get it with knee hard, and he'll bu 
ckle over very 
fast. 


Kidneys: A large nerve that branches off to the spinal cord comes very close to 
the skin at 
the kidneys. A direct blow with the knife edge of your hand can cause death. 


There are many more ways to kill and injure an enemy, but these should work best 
for the 

average person. This is meant only as information and I would not recommend that 
you use 

this for a simple High School Brawl. Use these methods only, in your opinion, if 
your life is in 

danger. Any one of these methods could very easily kill or cause permanent damag 
e to 
someone. One more word of caution, you should practice these moves before using 

them on a 

dummy, or a mock battle with a friend. (You don't have to actually hit him to pr 
actice, just 

work on accuracy.) 


41. Phone Systems Tutorial III by The Jolly Roger 


Preface: 


This article will focus primarily on the standard western electric single- Slot 
coin telephone 
(aka fortress fone) which can be divided into 3 types: 


dial-tone first (dtf 
coin-first (cf): (i.e., it wants your $ before you receive a dial tone) 
dial post-pay service (pp): you payafter the party answers 


Depositing coins (slugs): 


Once you have deposited your slug into a fortress, it is subjected to a Gamut of 
tests. The 


first obstacle for a slug is the magnetic trap. This will stop any light-weight 


magnetic slugs 


and coins. If it passes this, the slug is then classified as a nickel, dime, or 


Quarter. Each 


it will then 


slug is then checked for appropriate size 


and weight. If These tests are passed, 


travel through a nickel, dime, or quarter Magnet as appropriate. These ma 


et up an 


eddy current effect which Causes coins of the appropriate characteristics 


w down so 


they Will follow the correct trajectory. If all goes well, the coin will 


the Correct 


path (such as bouncing off of 


o the narrow 
accepted coin channel. 


The rat 


gnets s 
to slo 


follow 


the nickel anvil) where it will Hopefully f 


travels 


nies, which 


vives the 


Q KRZA 


to rotate 


own the Coin chute will 


ust then be retrieved using t 


her elaborate tests that are performed as t 


stop most slugs and other undesirable coins, suc 


he coin release lever. If the slug miraculo 


all int 
he coin 
h as Pe 


usly su 


amut, it will then strike the Appropriate totalizer arm causing a ratche 


once for every 5-cent increment (e.g., a quarter will cause it to rotate 


). The 


nal indicating 


e tones 


lsed at 12- 


kel causes 


17 pulses per second (pps). 


totalizer then causes the coin signal oscilla 


the value deposited to acts (a computer) or t 


t wheel 


5 times 


tor to readout a dual-frequency sig 
he Tsps operator. These are the sam 


used by phreaks in the infamous red boxes. For a quarter, 5 beep tones are outpu 


A dime causes 2 beep tones at 5 - 8« pps while a nic 


one beep tone at 5 - 8« pps. A beep consists of 2 tones: 2200 + 1700 hz. A relay 
in the 

fortress called the "B Relay" (yes, there is also an 'a relay') places a capacit 
or across the 

speech circuit during totalizer readout to prevent the "customer" from hearing t 
he red box 
tones. In older 3 slot phones: one bell (1050-1100 hz) for a nickel, two bells f 
or a dime, and 
one gong (800 hz) for a quarter are used instead of the modern dual-fregquency to 
nes. 


TSPS & ACTS 


While fortresses are connected to the co of the area, all transactions are handl 
ed via the 
traffic service position system (tsps). In areas that do not have acts, all call 
s that require 
operator assistance, such as calling card and collect, are automatically routed 
to a tsps 
operator position. In an effort to automate fortress service, a computer system 
known as 
automated coin toll service (acts) has been implemented in many areas. Acts list 
ens to the 
red box signals from the fones and takes appropriate action. It is acts which sa 
ys, "two 
dollars please (pause) please deposit two dollars for the next ten seconds" (and 
other 
variations). Also, if you talk for more than three minutes and then hang-up, act 
s will call 
back and demand your money. Acts is also responsible for automated calling card 
service. 
Acts also provide trouble diagnosis for craftspeople (repairmen specializing in 
fortresses). 
For example, there is a coin test which is great for tuning up red boxes. In man 
y areas this 
test can be activated by dialing 09591230 at a fortress (thanks to karl marx for 
this 
information). Once activated it will request that you deposit various coins. It 
wi then 
identify the coin and outpulse the appropriate red box signal. The coins are usu 
ally returned 
when you hang up. To make sure that there is actually money in the fone, the co 
initiates a 
"ground test" at various times to determine if a coin is actually in the fone. T 
his is why you 
must deposit at least a nickel in order to use a red box! 


Green Boxes: 


Paying the initial rate in order to use a red box (on certain fortresses) left a 
sour taste in 

many red boxer's mouths thus the green box was invented. The green box generates 
useful 

tones such as coin collect, coin return, and ringback. These are the tones that 
acts or the 


tsps operator would send to The co when appropriate. Unfortunately, the green bo 


x cannot 


be used at a fortress station but it must be used by the called party. 


Here are the tones: 


Coin Collect 700 + 1100 Hz 


Coin Return 1100 + 1700 Hz 


Ringback 700 + 1700 Hz 


Before the called party sends any of these tones, an operator released signal sh 


ould be sent 


to alert the MF detectors at the co. This can be accomplished by sending 900 + 1 


500 hz or 

a single 2600 hz wink (90 ms) followed by 
ignal for at 

least 900 Ms. 


Also, do not forget that the initial rate 
te period is 

up. Incidentally, once the above MF tones 
ch the co, 

they are converted into an appropriate dc 
lts for 


a 60 ms gap and then the appropriate s 


is coll 


for col 


pul 


Se 


(-130 volts for return & 


lected shortly before the 3 minu 


llecting and returning coins rea 


+130 vo 


collect). This pulse is then sent down the tip to the fortress. This causes the 


coin relay to 


either return or collect the coins. The alleged "t-network" takes advantage of t 
his 
information. When a pulse for coin collect (+130 vdc) is sent down the line, it 
must be 
grounded somewhere. This is usually either the yellow or black wire. Thus, if th 
e wires are 
exposed, these wires can be cut to prevent the pulse from being grounded. When t 
he three 

minute initial period is almost up, make sure that the black & yellow wires are 
severed; then 
hang up, wait about 15 seconds in case of a second pulse, reconnect the wires, p 
ick up the 

fone, hang up again, and if all goes well it should be "jackpot" time. 


Physical Attack: 


A typical fortress weighs roughly 50 lbs. With an empty coin box. Most of this i 
s accounted 
for in the armor plating. Why all the security? Well, Bell contributes it to the 
following: 
"social changes during the 1960's made the multislot coin station a prime target 
for: 
vandalism, strong arm robbery, fraud, and theft of service. This brought about t 
he 
introduction of the more rugged single slot coin station and a new environment f 
or coin 
service." As for picking the lock, I wi quote Mr. Phelps: "We often fantasize 
about ‘picking 
the lock' or 'getting a master key.' Well, you can forget about it. I don't like 
to discourage 
people, but it will save you from wasting a lot of our time--time which can be p 
ut to better 
use (heh, heh)." As for physical attack, the coin plate is secured on all four s 
ide by 
hardened steel bolts which pass through two 


slots each. These bolts are in turn interlocked by the main lock. One phreak I k 
now did 
manage to take one of the 'mothers' home (which was attached to a piece of plywo 
od at a 
construction site; otherwise, the permanent ones are a bitch to detach from the 
wall!). It 
took him almost ten hours to open the coin box using a power drill, sledge hamme 
rs, and 
crowbars (which was empty -- perhaps next time, he will deposit a coin first to 
hear if it 
slushes down nicely or hits the empty bottom with a clunk.) 


Taking the fone offers a higher margin of success. Although this may be difficul 
t often 

requiring brute force and there has been several cases of back axles being lost 
trying to 

take down a fone! A quick and dirty way to open the coin box is by using a shotg 
un. In 

Detroit, after ecologists cleaned out a municipal pond, they found 168 coin phon 


es rifled. In 

colder areas, such as Canada, some shrewd people tape up the fones using duct ta 
pe, pour in 

water, and come back the next day when the water will have froze thus expanding 
and 
cracking the fone open. In one case, "unauthorized coin collectors" where caught 
when they 
brought $6,000 in change to a bank and the bank became suspicious... At any rate 
, the main 

lock is an eight level tumbler located on the right side of the coin box. This l 
ock has 
390,625 possible positions (5 ^ 8, since there are 8 tumblers each with 5 possib 
le positions) 
thus it is highly pick resistant! The lock is held in place by 4 screws. If ther 
e is sufficient 
clearance to the right of the fone, it is conceivable to punch out the screws us 
ing the 

drilling pattern below (provided by Alexander Muddy in tap #32): 


aie es lll a Lin 


(Z) KEYHOLE (+) SCREWS 


After this is accomplished, the lock can be pushed backwards disengaging the loc 
k from the 


cover plate. The four bolts of the cover plate can then be retracted by turning 
the bolt 


works with a simple key in the shape of the hole on the coin plate (see diagram 
below). Of 


course, there are other methods and drilling patterns. 


[ ROUGHLY ] 


DIAGRAM OF COVER PLATE KEYHOLE 


The top cover uses a similar, but not as strong locking method with the keyhole 
depicted 


above on the top left hide and a regular lock (probably tumbler also) on the top 
right-hand 
side. It is interesting to experiment with the coin chute and the fortresses own 


"red box" 


which bell didn't have the balls to color red. 


Miscellaneous: 


In a few areas (rural 


ice, the 


& Canada), post-pay service exists. With this type of serv 


mouthpiece is cut off until the caller deposits money when the called party answ 


ers. This 


also allows for free calls to weather and other dial-it services! Recently, 2600 


magazine 


announced the c] 


p. It is 


lear box which consists of a telephone pickup coil and a small am 


based on the principal that the receiver is also a weak transmitter and that by 


amplifying 


your signal you can talk via the transmitter thus avoiding costly telephone char 


ges! Most 


fortresses are found in the 9xxx area. Under former bell areas, they usually sta 


rt at 98xx 


(right below the 99xx official series) and move downward. 


Since the line, not the fone, determines whether or not a deposit must be made, 


dtf & 


charge-a-call fones make great extensions! Finally, fortress fones allow foran 


ew hobby-- 
instruction 
da pair of 


P 


late col 


ecting. All that is required is a flat-head screwdriver an 


liers. S 


needle-nose 
hat you can 


P 


imply use the screwdriver to lift underneath the plate so t 


grab it with the pliers and yank downwards. I would suggest covering the tips of 
the pliers 

with electrical tape to prevent scratching. Ten cent plates are definitely becom 
ing a 

"rarity!" 


Fortress security: 


While a lonely fortress may seem the perfect target, beware! The gestapo has bee 
n known 

to stake out fortresses for as long as 6 years according to the grass roots quar 
terly. To 

avoid any problems, do not use the same fones repeatedly for boxing, calling car 
ds, & other 

experiments. The Telco knows how much money should be in the coin box and when i 
ts not 

there they tend to get perturbed (Read: Pissed Off). 


42. Black Box Plans by The Jolly Roger 


Introduction: 


At any given time, the voltage running through your phone is about 20 Volts. Whe 
n someone 

calls you, this voltage goes up to 48 Volts and rings the bell. When you answer, 
the voltage 

goes down to about 10 Volts. The phone company pays attention to this. When the 
voltage 

drops to 10, they start billing the person who called you. 


Function: 


The Black Box keeps the voltage going through your phone at 36 Volts, so that it 
never 

reaches 10 Volts. The phone company is thus fooled into thinking you never answe 
red the 

phone and does not bill the caller. However, after about a half hour the phone c 
ompany will 
get suspicious and disconnect your line for about 10 seconds. 


Materials: 


1 1.8K « Watt Resistor 
1 1«V LED 
1 SPST Switch 


Procedure: 


Open your phone by loosening the two screws on the bottom and lifting the case o 
ffs 


There should be three wires: Red, Green, and Yellow. We'll be working with the R 
ed Wire. 


Connect the following in parallel: 


The Resistor and LED. 
The SPST Switch. 


In other words, you should end up with this: 


(Red Wire) 


|---/\/\/\--0--! 


(Line) to) (Phone) 


l / : 


/\/\/\ = Resistor 


O = LED 


_/_ = SPST 


Use: 


The SPST Switch is the On/Off Switch of the Black Box. When the box is off, your 


phone 

behaves normally. When the box is on and your phone rings, the LED flashes. When 
you 

answer, the LED stays on and the voltage is kept at 36V, so the calling party do 
esn't get 

charged. When the box is on, you will not get a dial tone and thus cannot make c 
alls. Also 

remember that calls are limited to half an hour. 


PS Due to new Fone Company switching systems & the like, this may or may not wor 
k in your 

area. If you live in Bumfuck Kentucky, then try this out. I make no guarantees! 
(I never 

do...) 


43. The Infamous Blotto Box!! by The Jolly Roger 


(I bet that no one has the balls to build this one!) 


Finally, it is here! What was first conceived as a joke to fool the innocent 
phreakers around America has finally been conceived! Well, for you people who ar 


e 
unenlightened about the Blotto Box, here is a brief summery of a legend. 


The Blotto Box 


For years now every pirate has dreamed of the Blotto Box. It was at first made a 


s a joke to 

mock more ignorant people into thinking that the function of it actually was pos 
sible. Well, 
if you are The Voltage Master, it is possible. Originally conceived by King Blot 
to of much 
fame, the Blotto Box is finally available to the public. 


NOTE: Jolly Roger can not be responsible for the information disclosed in the fi 
e! This file 

is strictly for informational purposes and should not be actually built and used 
! Usage of 

this electronical impulse machine could have the severe results listed below and 
could result 
in high federal prosecution! Again, I TAKE NO RESPONSIBILITY! All right, now tha 
t that 
is cleared up, here is the basis of the box and it's function. 


The Blotto Box is every phreaks dream... you could hold AT&T down on its knee's 
with this 
device. Because, quite simply, it can turn off the phone lines everywhere. Nothi 


ng. Blotto. 
No calls wi be allowed out of an area code, and no calls will be allowed in. N 
o calls can be 

made inside it for that matter. As long as the switching system stays the same, 
this box wi 
not stop at a mere area code. It will stop at nothing. The electrical impulses t 
hat emit from 
this box wi open every line. Every line will ring and ring and ring... the vol 
tage will never be 


cut off until the box/generator is stopped. This is no 200 volt job, here. We ar 
e talking 
GENERATOR. Every phone line will continue to ring, and 


people close to the box may be electrocuted if they pick up the phone. But, the 
Blotto Box 

can be stopped by merely cutting of the line or generator. If they are cut off t 
hen nothing 
will emit any longer. It will take a while for the box to calm back down again, 
but that is 
merely a superficial aftereffect. Once again: Construction and use of this box i 
s not 
advised! The Blotto Box will continue as long as there is electricity to continu 
e with. OK, 
that is what it does, now, here are some interesting things for you to do with i 
AA 


Blotto Functions/Installing 


Once you have installed your Blotto, there is no turning back. The following are 
the 
instructions for construction and use of this box. Please read and heed all warn 
ings in the 

above section before you attempt to construct this box. 


Materials: 


A Honda portable generator or a main power outlet like in a stadium or some such 
place. 
400 volt rated coupler that splices a female plug into a phone line jack. 

A meter of voltage to attach to the box itself. 

A green base (i.e. one of the nice boxes about 3' by 4' that you see around in y 
our 
neighborhood. They are the main switch boards and would be a more effective line 
to 
start with or a regular phone jack (not your own, and not in your area code!) 
A soldering iron and much solder. 
A remote control or long wooden pole. 


Now. You must have guessed the construction from that. If not, here goes, I will 
explain in 

detail. Take the Honda Portable Generator and all of the other listed equipment 
and go out 
and hunt for a green base. Make sure it is one on the ground or hanging at head 
level from a 
pole, not the huge ones at the top of telephone poles. Open it up with anything 
convenient, if 

you are two feeble then fuck, don't try this. Take a look inside... you are hunt 
ing for color= 

coordinating lines of green and red. Now, take out your radio shack cord and rip 
the meter 


a. 


thing off. Replace it with the voltage meter about. A good level to set the volt 


age to is 

about 1000 volts. Now, attach the voltage meter to the cord and set the limit fo 
r one 

thousand. Plug the other end of the cord into the generator. Take the phone jack 
and splice 

the jack part off. Open it up and match the red and green wires with the other r 
ed and 

green wires. 


NOTE: If you just had the generator on and have done this in the correct order, 
you will be 

a crispy critter. Keep the generator off until you plan to start it up. Now, sol 
der those lines 

together carefully. Wrap duck tape or insulation tape around all of the wires. N 
ow, place the 

remote control right on to the startup of the generator. If you have the long po 
le, make 

sure it is very long and stand back as far away as you can get and reach the pol 
e over. 


NOTICE: If you are going right along with this without reading the file first, y 
ou still 

realize now that your area code is about to become null! Then, getting back, twi 
tch the 

pole/remote control and run for your damn life. Anywhere, just get away from it. 

It will be 

generating so much electricity that if you stand to close you will kill yourself 
The generator 


will smoke, etc. but will not stop. You are now killing your area code, because 
a of that 
energy is spreading through all of the phone lines around you in every direction 


Have a nice day! 


The Blotto Box: Aftermath 


Well, that is the plans for the most devastating and ultimately deadly 


box ever created. My hat goes off to: King Blotto (for the original idea). 


44, Blowgun by The Jolly Roger 


In this article I shall attempt to explain the use and manufacture of a powerful 
blow-gun 

and making darts for the gun. The possession of the blow gun described in this a 
rticle IS a 

felony. So be careful where you use it. I don't want to get you all busted. 


Needed: 


Several strands of yarn (About 2 inches a-piece). 


A regular pencil. 


A 2 7 inch long needle (hopefully with a beaded head. If not obtainable, wrap ta 
pe around 
end of needle. 


= foot pipe. (PVC or Aluminum) Half a inch in diameter. 


Constructing the dart: 


Carefully twist and pull the metal part (Along with eraser) of the pencil till i 
t comes off. 


Take Pin and start putting about 5-7 Strands of yarn on the pin. Then push them 
up to the 
top of the pin. But not over the head of the pin (or the tape). 


Push pin through the hollow part of the head where the pencil was before. 


That should for a nice looking dart. (see illustration) 


HH HTH 

>>>>>----- / # is the yarn 

> is the head of the pencil 
- is the pin it-self 


/ is the head of the pin 


Using the Darts: 


Now take the finished dart and insert it in the tube (if it is too small put on 
more yarn.) 


Aim the tube at a door, wall, sister, ect. 
Blow on the end of the pipe. 
Sometimes the end of the pipe may be sharp. When this happens I suggest you wrap 


it with 
some black electrician tape. It should feel a lot better. 


45. Brown Box Plans by The Jolly Roger 


This is a fairly simple mod that can be made to any phone. All it does is allow 
you to take any 

two lines in your house and create a party line. So far I have not heard of anyo 
ne who has 

any problems with it. There is one thing that you will notice when you are one o 
f the two 

people who is called by a person with a brown box. The other person will sound a 
little bit 

faint. I could overcome this with some amplifiers but then there wouldn't be ver 
y many of 

these made [Why not?]. I think the convenience of having two people on the line 
at once will 

make up for any minor volume loss. 


Here is the diagram: 


KEY: 


PART | SYMBOL | 


BLACK WIRE | * | 
YELLOW WIRE | = | 
RED WIRE | + | 
GREEN WIRE | - | 
SPDT SWITCH | _/_ | 
aie | 


VERTICAL WIRE | | | 


HORIZONTAL WIRE | _ | 


KKKKKK *_ /_++++++ 


PHONE 


46. Calcium Carbide Bomb by The Jolly Roger 


This is EXTREMELY DANGEROUS. Exercise extreme caution.... Obtain some calcium 
carbide. This is the stuff that is used in carbide lamps and can be found at nea 
rly any 


hardware store. Take a few pieces of this stuff (it looks like gravel) and put i 
t in a glass jar 
with some water. Put a lid on tightly. The carbide will react with the water to 
produce 


acetylene carbonate which is similar to the gas used in cutting torches. Eventua 
lly the glass 

with explode from internal pressure. If you leave a burning rag nearby, you will 
get a nice 

fireball! 


47. More Ways to Send a Car to Hell by The Jolly Roger 


Due to a lot of compliments, I have written an update to file #14. I have left t 
he original 
intact. This expands upon the original idea, and could be well called a sequel. 


How to have phun with someone else's car. If you really detest someone, and I me 
an 

detest, here's a few tips on what to do in your spare time. Move the windshield 
wiper 
blades, and insert and glue tacks. The tacks make lovely designs. If your "frien 
d" goes to 
school with you, Just before he comes out of school. Light a lighter and then pu 
t it directly 
underneath his car door handle. Wait...Leave...Listen. When you hear a loud "shi 
t!", you know 
he made it to his car in time. Remove his muffler and pour approximately 1 Cup o 
f gas in it. 
Put the muffler back, then wait till their car starts. Then you have a cigarette 
lighter. A 
30 foot long cigarette lighter. This one is effective, and any fool can do it. R 
emove the top 
a 
s 


ir filter. That's it! Or a oldie but goodie: sugar in the gas tank. Stuff rags 
oaked in gas up 
the exhaust pipe. Then you wonder why your "friend" has trouble with his/her lun 


Here's one that takes time and many friends. Take his/her car then break into th 
eir house 
and reassemble it, in their living or bedroom. Phun eh? If you're into engines, 
say eeni mine 
moe and point to something and remove it. They wonder why something doesn't work 
. There 
are so many others, but the real good juicy ones come by thinking hard. 


48. Ripping off Change Machines by The Jolly Roger 


Have you ever seen one of those really big changer machines in airports Laundrom 
ats or 
arcades that dispense change when you put in your 1 or 5 dollar bill? Well then, 


here is an 
article for you. 


Find the type of change machine that you slide in your bill length wise, not the 
type where 
you put the bill in a tray and then slide the tray in!!! 


After finding the right machine, get a $1 or $5 bill. Start crumpling up into a 
ball. Then 
smooth out the bill, now it should have a very wrinkly surface. 


Now the hard part. You must tear a notch in the bill on the left side about « in 
ch below the 
little 1 dollar symbol (See Figure). 


If you have done all of this right then take the bill and go out the machine. Pu 
t the bill in 

the machine and wait. What should happen is: when you put your bill in the machi 
ne it 
thinks everything is fine. When it gets to the part of the bill with the notch c 
ut out, 

the machine will reject the bill and (if you have done it right) give you the ch 
ange at the 


same time!!! So, you end up getting your bill back, plus the change!! It might t 
ake a little 
practice, but once you get the hang of it, you can get a lot of money! 


yassi Make notch here. About «" down from the 1. 


49, Clear Box Plans by The Jolly Roger 


The clear box is a new device which has just been invented that can be used thro 
ughout 
Canada and rural United States. The clear box works on "PostPay" payphones (fort 
ress 
fones). Those are the payphones that don't require payment until after the conne 
ction is 
established. You pick up the fone, get a dial tone, dial your number, and then i 
nsert your 

money after the person answers. If you don't deposit the money then you can not 

speak to 

the person on the other end because your mouth piece is cut off but not the ear- 
piece. 

(obviously these phones are nice for free calls to weather or time or other such 
recordings). 

All you must do is to go to your nearby Radio Shack, or electronics store, and g 
et a four- 

transistor amplifier and a telephone suction cup induction pick-up. The inductio 
n pick-up 

would be hooked up as it normally would to record a conversation, except that it 
would be 
plugged into the output of the amplifier and a microphone would be hooked to the 
input. So 

when the party that is being called answers, the caller could speak through the 

ittle 
microphone instead. His voice then goes through the amplifier and out the induct 
ion coil, 
and into the back of the receiver where it would then be broadcast through the p 
hone lines 
and the other party would be able to hear the caller. The Clear Box thus ‘clears 
up' the 
problem of not being heard. Luckily, the line wi not be cut-off after a certai 
n amount of 

time because it will wait forever for the coins to be put in. The biggest advant 
age for all of 
us about this new clear box is the fact that this type of payphone will most lik 
ely become 

very common. Due to a few things: 1st, it is a cheap way of getting the DTF, dia 
l-tone-first 

service, 2nd, it doesn't require any special equipment, (for the phone company) 

This 
payphone will work on any phone line. Usually a payphone line is different, but 


this is a 
regular phone line and it is set up so the phone does all the charging, not the 
company. 


50. CNA List by The Jolly Roger 


NPATEL NUMBERNPATEL NUMBERNPATEL NUMBER201201-676-7070415415-543- 

6374709*** NONE ***202304-343-7016416416—-443-0542712402-580-2255203203-789- 
6815417314-721-6626713713-861-7194204204-949-0900418514-725-2491714818-501- 
7251205205-988-7000419614-464-0123715608-252-6932206206-382-5124501405-236- 
6121716518-471-8111207617-787-5300502502-583-2861717412-633-5600208303-293- 
8777503206-382-5124718518-471-8111209415-543-2861504504-245-5330801303-293- 
8777212518-471-8111505303-293-8777802617-787-5300213415-781-5271506506-648- 


3041803912-784-0440214214-464-7400507402-580-2255804304-344-7935215412-633- 
5600509206-382-5124805415-543-2861216614-464-0123512512-828-2501806512-828- 
2501217217-525-5800513614-464-0123807416-443-0542218402-580-2255514514-725- 
2491808212-334-4336219317-265-4834515402-580-2255809212-334-4336301304-343- 
1401516518-471-8111812317-265-4834302412-633-5600517313-223-8690813813-228- 
7871303303-293-8777518518-471-8111814412-633-5600304304-344-8041519416-443- 
0542815217-525-5800305912-784-0440601601-961-8139816816-275-2782306306-347- 
2878602303-293-8777817214-464-7400307303-293-8777603617-787-5300818415-781- 
5271308402-580-2255604604-432-2996819514-725-2491309217-525-5800605402-580- 
2255901615-373-5791312312-796-9600606502-583-2861902902-421-4110313313-223- 
8690607518-471-8111904912-784-0440314314-721-6626608608-252-6932906313-223- 
8690315518-471-8111609201-676-7070907*** NONE ***316816-275-2782612402-580- 
2255912912-784-0440317317-265-4834613416-443-0542913816-275-2782318504-245- 
5330614614-464-0123914518-471-8111319402-580-2255615615-373-5791915512-828- 
2501401617-787-5300616313-223-8690916415-543-2861402402-580-2255617617-787- 
5300918405-236-6121403403-425-2652618217-525-5800919912-784-0440404912-784- 
0440619818-501-7251900201-676-7070405405-236-6121701402-580-2255406303-293- 
8777702415-543-2861408415-543-6374703304-344-7935409713-861-7194704912-784- 
0440412413-633-5600705416-979-3469413617-787-5300706*** NONE ***414608-252- 
6932707415-543-6374 


51. Electronic Terrorism by The Jolly Roger 


It starts when a big, dumb lummox rudely insults you. Being of a rational, intel 
ligent 

disposition, you wisely choose to avoid a (direct) confrontation. But as he laug 
hs in your 

face, you smile inwardly---your revenge is already planned. 


Follow your victim to his locker, car, or house. Once you have chosen your targe 
t site, lay 
low for a week or more, letting your anger boil. 


In the mean time, assemble your versatile terrorist kit (details below.) 


lant your kit at the designated target site on a Monday morning between the hou 
m and 6200 am. Include a calm, suggestive note that quietly hints at the possib 
ee ee: Do not write it by hand! An example of an effective note: "don't 
at a jerk, or the next one will take off your hand. Have a nice day." Notice h 
ee instills fear. As if written by a homicidal psychopath. 


H- KD 


Choose a strategic location overlooking the target site. Try to position yoursel 
f in such a 
way that you can see his facial contortions. 


Sit back and enjoy the fireworks! Assembly of the versatile, economic, and effec 
tive 
terrorist kit #1: the parts you'll need are: 


4 AA batteries 


[| 1 9-volt battery 


1 SPDT mini relay (radio shack) 


1 rocket engine (smoke bomb or m-80) 


1 solar igniter (any hobby store) 
1 9-volt battery connector 


Take the 9-volt battery and wire it through the relay's coil. This circuit shoul 
d also include 
a pair of contacts that when separated cut off this circuit. These contacts shou 
ld be 
held together by trapping them between the locker, mailbox, or car door. Once th 
e door 
is opened, the contacts fall apart and the 9-volt circuit is broken, allowing th 
e relay to 

fall to the closed position thus closing the ignition circuit. (If all this is c 
onfusing take a 

look at the schematic below.) 


Take the 4 AA batteries and wire them in succession. Wire the positive terminal 
of one to 

the negative terminal of another, until all four are connected except one positi 
ve 
terminal and one negative terminal. Even though the four AA batteries only combi 
ne to 
create 6 volts, the increase in amperage is necessary to activate the solar igni 
ter 

quickly and effectively. 


Take the battery pack (made in step 2) and wire one end of it to the relay's sin 
gle pole and 

the other end to one prong of the solar igniter. Then wire the other prong of th 
e solar 
igniter back to the open position on the relay. 


Using double sided carpet tape mount the kit in his locker, mailbox, or car door 
. And last, 
insert the solar igniter into the rocket engine (smoke bomb or m-80). 


Your kit is now complete! 
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52. How to Start A Conference w/o 2600hz or M-F by The Jolly Roger 


This method of starting the conf. Depends on your ability to bullshit the operat 
or into 

dialing a number which can only be reached with an operator's M-F tones. When bu 
lshitting 

the operator remember operator's are not hired to think but to do. 


Here is a step-by-step way to the conf.: 


Ca the operator through a pbx or extender, you could just call one Through you 
r line but I 
wouldn't recommend it. 


Say to the operator: TSPS maintenance engineer, ring-forward to 213+080+1100, po 
sition 
release, thank you. (she will probably ask you for the number again) Definitions: 


Ring-forward instructs her to dial the number. 


Position release instructs her to release the trunk after she has dialed the num 
ber. 


+ - remember to say 213plus080 plus1100. 


3. When you are connected with the conf. You will here a whistle blow twice and 
a recording 
asking you for your operator number. Dial in any five digits and hit the pounds 
sign a couple 
of times. Simply dial in the number of the billing line ect. When the recording 
ask for it. 
When in the control mode of the conf. Hit '6' to transfer control. Hit '001' to 
reenter the 
number of conferee's and time amount which you gave when you stared the conf. Re 
member 

the size can be from 2-59 conferee's. I have not found out the 'lengths' limits. 


53. How to Make Dynamite by The Jolly Roger 


Dynamite is nothing more than just nitroglycerin and a stabilizing agent to make 
it much 

safer to use. The numbers are percentages, be sure to mix these carefully and be 
sure to 

use the exact amounts. These percentages are in weight ratio, not volume. 


NumberIngredientsAmountlstNitroglycerin32% Sodium Nitrate28% Woodmeall10% 
Ammonium Oxalate29% Guncotton1l%2ndNitroglycerin24% Potassium Nitrate9% Sodium 
Nitrate56% Woodmeal9% Ammonium Oxalate2%3rdNitroglycerin35«% Potassium 
Nitrate44«% Woodmeal6% Guncotton2«% Vaseline5«% Powdered 
Charcoal6%4thNitroglycerin25% Potassium Nitrate26% Woodmeal34% Barium Nitrate5% 
Starchl0%5thNitroglycerin57% Potassium Nitratel9% Woodmeal9% Ammonium 
Oxalatel2% Guncotton3%6thNitroglycerinl8% Sodium Nitrate70% Woodmeal5«% 
Potassium Chloride4«% Chalk2%7thNitroglycerin26% Woodmeal40% Barium Nitrate32% 
Sodium Carbonate2%8thNitroglycerin44% Woodmeall12% Anhydrous Sodium 


Sulfate44%9thNitroglycerin24% Potassium Nitrate32«% Woodmeal33«% Ammonium 
Oxalatel0%l0thNitroglycerin26% Potassium Nitrate33% 
Woodmeal41%1l1thNitroglycerin15% Sodium Nitrate62.9% Woodmeal21.2% Sodium 
Carbonate. 9%12thNitroglycerin35% Sodium Nitrate27% Woodmeal10% Ammonium 
Oxalatel%13thNitroglycerin32% Potassium Nitrate27% Woodmeall0% Ammonium 
Oxalate30% Guncotton1%14thNitroglycerin33% Woodmeall0.3% Ammonium Oxalate29% 
Guncotton.7% Potassium Perchloride27%15thNitroglycerin40% Sodium Nitrate45% 
Woodmeal15%1l6thNitroglycerin47% Starch50% Guncotton3%17thNitroglycerin30% 
Sodium Nitrate22.3% Woodmeal40«% Potassium Chloride7.2%18thNitroglycerin50% 
Sodium Nitrate32.6% Woodmeal17% Ammonium Oxalate.4%19thNitroglycerin23% 
Potassium Nitrate27«sWoodmeal37% Ammonium Oxalate8% Barium Nitrate4% Calcium 
Carbonate«% 


If you can't seem to get one or more of the ingredients try another one. If you 
still can't, 
you can always buy small amounts from your school, or maybe from various chemica 
1 

companies. When you do that, be sure to say as little as possible, if during the 
school year, 

and they ask, say it's for a experiment for school. 


54. Auto Exhaust Flame Thrower by The Jolly Roger 


For this one, all you need is a car, a spark plug, ignition wire and a switch. I 
nstall the spark 

plug into the last four or five inches of the tail pipe by drilling a hole that 
the plug can 
screw into easily. Attach the wire (this is regular insulated wire) to one side 
of the switch 
and to the spark plug. The other side of the switch is attached to the positive 
terminal on 
the battery. With the car running, simply hit the switch and watch the flames fl 
y!!! Again be 

careful that no one is behind you! I have seen some of these flames go 20 feet!! 


55. Breaking into BBS Express by The Jolly Roger 


If you have high enough access on any BBS Express BBS you can get the Sysop's pa 
ssword 

without any problems and be able to log on as him and do whatever you like. Down 
load the 

Pass file, delete the whole BBS, anything. Its all a matter of uploading a text 
file and 

downloading it from the BBS. You must have high enough access to see new uploads 
to do 

this. If you can see a file you just uploaded you have the ability to break into 
the BBS ina 

few easy steps. Why am I telling everyone this when I run BBS Express myself? We 


11 there 

is one way to stop this from happening and I want other Sysops to be aware of it 
and not 

have it happen to them. Breaking in is all based on the MENU function of BBS Exp 
ress. 

Express will let you create a menu to display different text files by putting th 
e word MENU 

at the top of any text file and stating what files are to be displayed. But due 
to a major 

screw up by Mr. Ledbetter you can use this MENU option to display the USERLOG an 
d the 

Sysop's Passwords or anything else you like. I will show you how to get the Syso 
p's pass and 

therefore log on as the Sysop. BBs Express Sysop's have 2 passwords. One like ev 
eryone 
else gets in the form of X1XXX, and a Secondary password to make it harder to ha 
ck out 

the Sysops pass. The Secondary pass is found in a file called SYSDATA.DAT. This 
file must 

be on drive 1 and is therefore easy to get. 


All you have to do is upload this simple Text file: 


MENU 


1 


D1:SYSDATA.DAT 


Rip-off time! 


After you upload this file you download it non-Xmodem. Stupid Express thinks 


it is displaying a menu and you will see this: 


Rip-off time! 


Selection [0]: 


Just hit 1 and Express will display the SYSDATA.DAT file. OPPASS is where the Sy 
sop's 

Secondary pass will be. 
number 
of the USERLOG.DAT file. The Sysop might have renamed this file or put it ina 
Subdirectory or even on a different drive. I Will Assume he left it as D1:USERLO 
G.DAT. 
The other parts of this file tell you where the .HLP screens are and where the L 
OG is saved 

and all the Download path names. 


iw) 


1:USERLOG.DAT is where you will find the name and Drive 


Now to get the Sysop's primary pass you upload a text file like this: 


MENU 


1 


D1:USERLOG. DAT 


Breaking into Bedwetter's BBS 


Again you then download this file non-Xmodem and you will see: 


Breaking into Bedwetter's BBS 


Selection [0]: 


You then hit 1 and the long USERLOG.DAT file comes flying at you. The Sysop is t 
he first 
entry in this very long file so it is easy. You will see: 


SYSOP'S NAME X1XXX 


You should now have his 2 passwords. 


There is only one easy way out of this that I can think of, and that is to make 
all new 

uploads go to SYSOP level (Level 9) access only. This way nobody can pull off wh 
at I just 

explained. I feel this is a major Bug on Mr. Ledbetter's part. I just don't know 
why no one 

had thought of it before. I would like to give credit to Redline for the message 
he left on 


Modem Hell telling about this problem, and also to Unka for his ideas and input 
about 
correcting it. 


56. Firebombs by The Jolly Roger 


Most fire bombs are simply gasoline filled bottles with a fuel soaked rag in the 
mouth (the 
bottle's mouth, not yours). The original Molotov cocktail, and still about the b 
est, was a 

mixture of one part gasoline and one part motor oil. The oil helps it to cling t 
o what it 

splatters on. Some use one part roofing tar and one part gasoline. Fire bombs ha 
ve been 

found which were made by pouring melted wax into gasoline. 


57. Fuse Ignition Bomb by The Jolly Roger 


A four strand homemade fuse is used for this. It burns like fury. It is held dow 
n and 

concealed by a strip of bent tin cut from a can. The exposed end of the fuse is 
ipped into 

the flare igniter. To use this one, you light the fuse and hold the fire bomb un 
til the fuse 

has burned out of sight under the tin. Then throw it and when it breaks, the bur 
n 

w 


[ox 


ing fuse 
l ignite the contents. 


58. Generic Bomb by The Jolly Roger 


Acquire a glass container. 

Put in a few drops of gasoline. 

Cap the top. 

Now turn the container around to coat the inner surfaces and then evaporates. 


Add a few drops of potassium permanganate (Get this stuff from a snake bite kit) 


The bomb is detonated by throwing against a solid object. 


After throwing this thing, run like hell. This thing packs about « stick of dyna 
mite. 


59. Green Box Plans by the Jolly Roger 


Paying the initial rate in order to use a red box (on certain fortresses) left a 
sour taste in 

many red boxers mouths, thus the green box was invented. The green box generates 
useful 

tones such as COIN COLLECT, COIN RETURN, AND RINGBACK. These are the tones that 

ACTS or the TSPS operator would send to the CO when appropriate. Unfortunately, 

the 

green box cannot be used at the fortress station but must be used by the CALLED 

party. 


Here are the tones: 


COIN COLLECT 700+1100hz 


COIN RETURN 1100+1700hz 


RINGBACK 700+1700hz 


Before the called party sends any of these tones, an operator release signal sho 
uld be sent 
to alert the MF detectors at the CO. This can be done by sending 900hz + 1500hz 
or a 
single 2600 wink (90 ms.) Also do not forget that the initial rate is collected 
shortly before 
the 3 minute period is up. Incidentally, once the above MF tones for collecting 
and returning 
coins reach the CO, they are converted into an appropriate DC pulse (-130 volts 
for return 
and +130 for collect). This pulse is then sent down the tip to the fortress. Thi 
s causes the 
coin relay to either return or collect the coins. The alleged "T-network" takes 
advantage of 
this information. When a pulse for coin collect (+130 VDC) is sent down the line 
, it must be 
grounded somewhere. This is usually the yellow or black wire. Thus, if the wires 
are 
xposed, these wires can be cut to prevent the pulse from being grounded. When t 
he three 
minute initial period is almost up, make sure that the black and yellow wires ar 
e severed, 
then hang up, wait about 15 seconds in case of a second pulse, reconnect the wir 
es, pick up 
the phone, and if all goes well, it should be "JACKPOT" time. 


60. Portable Grenade Launcher by The Jolly Roger 


If you have a bow, this one is for you. Remove the ferrule from an aluminum arro 
w, and fill 

the arrow with black powder (I use grade FFFF, it burns easy)and then glue a sho 
tshell 

primer into the hole left where the ferrule went. Next, glue a BB on the primer, 
and you are 
ready to go! Make sure no one is nearby.... Little shreds of aluminum go all ove 
r the place!! 


61. Hacking Tutorial by The Jolly Roger 


What is hacking? 


According to popular belief the term hacker and hacking was founded at MIT it co 
mes from 

the root of a hack writer, someone who keeps "hacking" at the typewriter until h 
e finishes 

the story. A computer hacker would be hacking at the keyboard or password works. 


What you need: 


To hack you need a computer equipped with a modem (a device that lets you transm 
it data 
over phone lines) which should cost you from $100 to $1200. 


How do you hack? 


Hacking requires two things: 


The phone number. 


Answer to identity elements. 


How do you find the phone number? 


There are three basic ways to find a computers phone number: 
Scanning 
Directory 


Inside info 


What is scanning? 


Scanning is the process of having a computer search for a carrier tone. For exam 
ple, the 

computer would start at (800) 111-1111 and wait for carrier if there is none it 
will go on to 

111-1112 etc. If there is a carrier it will record it for future use and continu 
e looking for 

more. 


What is directory assistance? 


This way can only be used if you know where your target computer is. For this 


example say it is in menlo park, CA and the company name is Sri. 


Dial 411 (or 415-555-1212) 

Say "Menlo park" 

Say "Sri" 

Write down number 

Ask if there are any more numbers 
If so write them down. 

Hang up on operator 

Dial all numbers you were given 


Listen for carrier tone 


If you hear carrier tone write down number, call it on your modem and your set t 
o hack! 


62. The Basics of Hacking II by The Jolly Roger 


Basics to know before doing anything, essential to your continuing career as one 
of the elite 
in the country... This article, "The introduction to the world of hacking." is m 
eant to help 
you by telling you how not to get caught, what not to do on a computer system, w 
hat type of 
equipment should I know about now, and just a little on the history, past presen 
t future, of 

the hacker. 


Welcome to the world of hacking! We, the people who live outside of the normal r 
ules, and 

have been scorned and even arrested by those from the ‘civilized world', are bec 
oming 

scarcer every day. This is due to the greater fear of what a good hacker (skill 

wise, no 
moral judgments here) can do nowadays, thus causing anti- hacker sentiment in th 
e masses. 

Also, few hackers seem to actually know about the computer systems they hack, or 
what 
equipment they will run into on the front end, or what they could do wrong on a 
system to 
alert the 'higher' authorities who monitor the system. This article is intended 
to tell you 
about some things not to do, even before you get on the system. I will tell you 

about the 

new wave of front end security devices that are beginning to be used on computer 
s. I will 

attempt to instill in you a second identity, to be brought up at time of great n 
eed, to pull 
you out of trouble. And, by the way, I take no, repeat, no, responsibility for w 
hat we say in 

this and the forthcoming articles. 


Enough of the bullshit, on to the fun: after logging on your favorite bbs, you s 
ee on the high 
access board a phone number! It says it's a great system to "fuck around with!" 
This may 
be true, but how many other people are going to call the same number? So: try to 
avoid 
calling a number given to the public. This is because there are at least every o 
ther user 
calling, and how many other boards will that number spread to? If you call a num 
ber far, far 


away, and you plan on going through an extender or a re-seller, don't keep calli 
ng the same 

access number (I.E. As you would if you had a hacker running), this looks very s 
uspicious and 

can make life miserable when the phone bill comes in the mail. Most cities have 
a variety of 

access numbers and services, so use as many as you can. Never trust a change in 
the 

system... The 414's, the assholes, were caught for this reason: when one of them 
connected 

to the system, there was nothing good there. The next time, there was a trek gam 
e stuck 
right in their way! They proceeded to play said game for two, say two and a half 
hours, 
while telenet was tracing them! Nice job, don't you think? If anything looks sus 
picious, drop 


th ine immediately!! As in, yesterday!! The point we're trying to get across i 
s: if you use a 

little common sense, you won't get busted. Let the little kids who aren't smart 
enough to 


recognize a trap get busted, it will take the heat off of the real hackers. Now, 
let's say you 
get on a computer 


system... It looks great, checks out, everything seems fine. OK, now is when it 
gets more 

dangerous. You have to know the computer system to know what not to do. Basicall 
Y, keep 

away from any command something, copy a new file into the account, or whatever! 

Always 

leave the account in the same status you logged in with. Change *nothing*... If 

it isn't an 
account with priv's, then don't try any commands that require them! All, yes all 
, systems are 

going to be keeping log files of what users are doing, and that will show up. It 
is just like 
dropping a trouble-card in an ESS system, after sending that nice operator a pre 

tty tone. 

Spend no excessive amounts of time on the account in one stretch. Keep your call 
ing to the 

very late night if possible, or during business hours (believe it or not!). It s 
o happens that 
there are more users on during business hours, and it is very difficult to read 
a log file with 

60 users doing many commands every minute. Try to avoid systems where everyone k 
nows 
each other, don't try to bluff. And above all: never act like you own the system 
, or are the 


best there is. They always grab the people who's heads swell... There is some ve 
ry 

interesting front end equipment around nowadays, but first let's define terms... 
By front 

end, we mean any device that you must pass through to get at the real computer. 


There are 

devices that are made to defeat hacker programs, and just plain old multiplexers 

. To defeat 

hacker programs, there are now devices that pick up the phone and just sit there 
. This 

means that your device gets no carrier, thus you think there isn't a computer on 


the other 

end. The only way around it is to detect when it was picked up. If it picks up a 
fter the 

same number ring, then you know it is a hacker-defeater. These devices take a mu 


lti-digit 

code to let you into the system. Some are, in fact, quite sophisticated to the p 
oint where it 

will also limit the user name's down, so only one name or set of names can be va 
lid logins 

after they input the code... Other devices input a number code, and then they di 
al back a 

pre-programmed number for that code. These systems are best to leave alone, beca 
use they 

know someone is playing with their phone. You may think "but I'll just reprogram 


the dial- 


back." Think again, how stupid that is... Then they have your number, or a test 
loop if you 
were just a little smarter. If it's your number, they have your balls (if male.. 


.), 1£ its a loop, 
then you are screwed again, since those loops 


are *monitored*. As for multiplexers... What a plexer is supposed to do is this: 


The system can accept multiple users. We have to time share, so we'll let the fr 
ont-end 


processor do it... Well, this is what a multiplexer does. Usually they will ask 
for something 
like "enter class" or "line:". Usually it is programmed for a double digit numbe 


r, or a four to 
five letter word. There are usually a few sets of numbers it accepts, but those 
numbers also 

set your 300/1200/2400 baud data type. These multiplexers are inconvenient at be 


st, so 


not to worry. A little about the history of hacking: hacking, by my definition, 
means a great 

knowledge of some special area. Doctors and lawyers are hackers of a sort, by th 
is 

definition. But most often, it is being used in the computer context, and thus w 
e have a 
definition of "anyone who has a great amount of computer or telecommunications 
knowledge." You are not a hacker because you have a list of codes... Hacking, by 
my 
definition, has then been around only about 15 years. It started, where else but 
, MIT and 
colleges where they had computer science or electrical engineering departments. 
Hackers 

have created some of the best computer languages, the most awesome operating sys 
tems, 
and even gone on to make millions. Hacking used to have a good name, when we cou 
ld 
honestly say "we know what we are doing". Now it means (in the public eye): the 
414"'s, Ron 

Austin, the NASA hackers, the arpanet hackers... All the people who have been ca 
ught, have 

done damage, and are now going to have to face fines and sentences. Thus we come 
past the 

moralistic crap, and to our purpose: educate the hacker community, return to the 
days 

when people actually knew something... 


63. Hacking DEC's by The Jolly Roger 


In this article you will learn how to log in to dec's, logging out, and all the 
fun stuff to do in- 
between. All of this information is based on a standard dec system. Since there 
are dec 

systems 10 and 20, and I favor, the dec 20, there will be more info on them in t 
his article. 

It just so happens that the dec 20 is also the more common of the two, and is us 
ed by much 

more interesting people (if you know what I mean...) OK, the first thing you wan 
t to do when 

you are receiving carrier from a dec system is to find out the format of login n 
ames. You 

can do this by looking at who is on the system. 


Dec=> ` (the 'exec' level prompt) 


you=> sy 


sy: short for sy(stat) and shows you the system status. 


You should see the format of login names. A systat usually comes up in this form 


Job Line Program User 


Job: The job number (not important unless you want to log them off later) 


Line: What line they are on (used to talk to them...) These are both two or thre 
e digit 
numbers. 


Program: What program are they running under? If it says 'exec' they aren't doin 


g 
anything at all... 


User: ahhhahhhh! This is the user name they are logged in under... Copy the form 
at, and 
hack yourself outa working code... Login format is as such: 


dec=> ` 


you=> login username password 


Username is the username in the format you saw above in the systat. After you hi 

t the 

space after your username, it will stop echoing characters back to your screen. 
This is the 

password you are typing in... Remember, people usually use their name, their dog 
"s name, 

the name of a favorite character in a book, or something like this. A few clever 
people have 

it set to a key cluster (qwerty or asdfg). Passwords can be from 1 to 8 characte 
rs long, 

anything after that is ignored. You are finally in... It would be nice to have a 
little help, 


wouldn't it? Just type a ? Or the word help, and it will give you a whole list o 
D COPLESis.% 

Some handy characters for you to know would be the control keys, wouldn't it? Ba 
ckspace 


on a dec 20 is rub which is 255 on your ASCII chart. On the dec 10 it is control 
-H. To abort 

a long listing or a program, control-C works fine. Use Control-0O to stop long ou 
tput to the 
terminal. This is handy when playing a game, but you don't want to control-C out 
. Control-T 


for the time. Control-u will kill the whole line you are typing at the moment. Y 
ou may 
accidentally run a program where the only way out is a control-X, so keep that i 


n reserve. 
Control-s to stop listing, control-Q to continue on both systems. Is your termin 
al having 
trouble?? Like, it pauses for no reason, or it doesn't backspace right? This is 
because both 
systems support many terminals, and you haven't told it what yours is yet... You 
are using a 
VT05 so you need to tell it you are one. 


Dec=> ` 
you=> information terminal 

oie 
You=> info 

(This shows you what your terminal is set up as.) 
Dec=>all sorts of shit, then the ` 
you=> set ter vt05 


(This sets your terminal type to VT05.) 


Now let's see what is in the account (here after abbreviated acct.) that you hav 
e hacked 
onto. Say: 


=> dir 


(Short for directory.) 


It shows you what the user of the code has save to the disk. There should be a f 
ormat like 

this: xxxxx.00oxxxxx is the file name, from 1 to 20 characters long. Ooo is the 
file type, 

one of: exe, txt, dat, bas, cmd and a few others that are system dependant. Exe 
is a 

compiled program that can be run (just by typing its name at the `) 


Txt is a text file, which you can see by typing: 
=>type xxxxx.Txt 

Do not try to: 

=>type XXxXxx.Exe 


(This is very bad for your terminal and will tell you absolutely nothing.) 


Dat is data they have saved. 
Bas is a basic program, you can have it typed out for you. 


Cmd is a command type file, a little too complicated to go into here. Try: 


=>take xxxxx.Cmd 


By the way, there are other users out there who may have files you can use. 


(Gee, why else am I here?) 


=> dir <*.*> (Dec 20) 


=> dir [*,*] (Dec 10) 


* is a wildcard, and will allow you to access the files on other accounts if the 
user has it set 

for public access. If it isn't set for public access, then you won't see it. To 
run that 

program: 


dec=> ` 


you=> username program-name 


Username is the directory you saw the file listed under, and file name was what 
else but the 

file name? ** You are not alone ** remember, you said (at the very start) sy sho 
rt for 

systat, and how we said this showed the other users on the system? Well, you can 
talk to 

them, or at least send a message to anyone you see listed in a systat. You can d 
o this by: 


dec=> the user list (from your systat) 
you=> talkusername (Dec 20) 


send username (Dec 10) 


Talk allows you and them immediate transmission of whatever you/they type to be 
sent to 

the other. Send only allow you one message to be sent, and send, they will send 

back to you, 

with talk you can just keep going. By the way, you may be noticing with the talk 
command 
that what you type is still acted upon by the parser (control program). To avoid 
the 
constant error messages type either: 


you=> ;your message 


you=> rem your message 


the semi-colon tells the parser that what follows is just a comment. Rem is shor 
t for 

"remark' and ignores you from then on until you type a control-Z or control-C, a 
t which 
point it puts you back in the exec mode. To break the connection from a talk com 
mand type: 


you=> break priv's: 


If you happen to have privs, you can do all sorts of things. First of all, you h 
ave to activate 
those privs. 


You=> enable 


This gives you a $ prompt, and allows you to do this: whatever you can do to you 
r own 

directory you can now do to any other directory. To create a new acct. Using you 
r privs, just 

type: 


=>build username 


If username is old, you can edit it, if it is new, you can define it to be whate 
ver you wish. 
Privacy means nothing to a user with privs. By the way, there are various levels 
of privs: 
operator, wheel, cia. Wheel is the most powerful, being that he can log in from 
anywhere 
and have his powers. Operators have their power because they are at a special te 
rmina 
allowing them the privs. Cia is short for 'confidential information access', whi 
ch allows you 
a low level amount of privs. Not to worry though, since you can read the system 
og file, 
which also has the passwords to all the other accounts. 


To de-activate your privs, type: 


you=> disable 


when you have played your greedy heart out, you can finally leave the 


system with the command: 


=>logout 


This logs the job you are using off the system (there may be varients of this su 
ch as kjob, 
or killjob.) 


64. Harmless Bombs by The Jolly Roger 


To all those who do not wish to inflict bodily damage on their victims but only 
terror. These 
are weapons that should be used from high places. 


The Flour Bomb 


Take a wet paper towel and pour a given amount of baking flour in the center. Th 
en wrap it 

up and put on a rubber band to keep it together. When thrown it will fly well bu 
when it 
hits, it covers the victim with the flower or causes a big puff of flour which w 
ill put the 
v 
S 


ct 


ictim in terror since as far as they are concerned, some strange white powder i 
all 
over them. This is a cheap method of terror and for only the cost of a roll of p 
aper 
towels and a bag of flour you and your friends can have loads of fun watching pe 
ople 

flee in panic. 


Smoke Bomb Projectile 


All you need is a bunch of those little round smoke bombs and a wrist rocket or 
any sling- 
shot. Shoot the smoke bombs and watch the terror since they think it will blow u 
p! 


Rotten Eggs (Good ones) 


Take some eggs and get a sharp needle and poke a small hole in the top of each o 
ne. Then let 

them sit in a warm place for about a week. Then you've got a bunch of rotten egg 
s that 

will only smell when they hit. 


Glow in the Dark Terror 


Take one of those tubes of glow in the dark stuff and pour the stuff on whatever 


you want 


to throw and when it gets on the victim, they think it's some deadly chemical or 


a 


radioactive substance so they run in total panic. This works especially well wit 


h flower 


bombs since a gummy, glowing substance gets all over the victim. 


Fizzling Panic 


Take a baggy of a water-baking soda solution and seal it. (Make sure there is no 


air in it 


Ee 


since the solution will form a gas and you don't want it to pop on you.) Then pu 


t it ina 


bigger plastic bag and fill it with vinegar and seal it. When thrown, the two su 


bstances 


will mix and cause a violently bubbling substance to go all over the victim. 


65. Breaking Into Houses by The Jolly Roger 


Okay You Need: 
Tear Gas or Mace 
A BB/Pellet Gun 
An Ice Pick 


Thick Gloves 


What You Do Is: 


Call the house, or ring doorbell, to find out if they're home. 


If they're not home then... 


Jump over the fence or walk through gate (whatever). 


If you see a dog give him the mace or tear gas. 


Put the gloves on!!!!I1!! 


Shoot the BB gun slightly above the window locks. 


Push the ice-pick through the hole (made by the BB gun). 


Enter window. 


FIRST...Find the LIVING ROOM. (there're neat things there!). 
Goto the bedroom to get a pillow case. Put the goodies in the pillow case. 


Get out <-* FAST! -*> 


Notes: You should have certain targets worked out (like computers, Radios, Ect.) 
Also <-* 

NEVER *-> Steal from your own neighborhood. If you think they have an alarm...<- 
* FORGET 

IT! *->, 


66. A Guide to Hypnotism by The Jolly Roger 


What hypnotism is? 


Hypnotism, contrary to common belief, is merely state when your mind and body ar 
e ina 

state of relaxation and your mind is open to positive, or cleverly worded negati 
ve, 

influences. It is not a trance where you: 


Are totally influenceable. 


Cannot lie. 
A sleep which you cannot wake up from without help. 


This may bring down your hope somewhat, but, hypnotism is a powerful for self he 
lp, and/or 
mischief. 


Your subconscious mind 


Before going in further, I'd like to state that hypnotism not only is great in t 
he way that it 

relaxes you and gets you (in the long run) what you want, but also that it taps 

a force of 

incredible power, believe it or not, this power is your subconscious mind. The s 
ubconscious 

mind always knows what is going on with every part of your body, every moment of 
the day. 

It protects you from negative influences, and retains the power to slow your hea 
rtbeat 

down and stuff like that. The subconscious mind holds just about all the info yo 
u would like 

to know 


About yourself, or, in this case, the person you will be hypnotizing. There are 

many ways to 

talk to your subconscious and have it talk back to you. One way is the ouja boar 

d, no its not 

a spirit, merely the minds of those who are using it. Another, which I will disc 

uss here, is 

the pendulum method. OK, here is how it goes. First, get a ring or a washer and 

tie it toa 

thread a little longer than half of your forearm. Now, take a sheet of paper and 

draw a big 

circle in it. In the big circle you must now draw a crosshair (a big +). Now, pu 

t the sheet of 

paper on a table. Next, hold the thread with the ring or washer on it and place 

it (holding 
the thread so that the ring is 1 inch above the paper swinging) in the middle of 
the 

crosshair. Now, swing the thread so the washer goes up and down, say to yourself 
the word 

"Yes" now, do it side to side and say the word "no". Do it counter clockwise and 
say "I don't 

know". And lastly, do it clockwise and say "I don't want to say." Now, with the 

thread back 

in the middle of the crosshair, ask yourself questions and wait for the pendulum 

to swing in 
the direction for the answer. (yes, no, I don't know or I don't want to say...). 

Soon, to your 

amazement, it will be answering questions like anything... Let the pendulum answ 
er, don't 

try.. When you try you will never get an answer. Let the answer come to you. 


How to induce hypnotism 


Now that you know how to talk to your subconscious mind, I will now tell you how 
to guide 
someone into hypnosis. Note that I said guide, you can never, hypnotize someone, 
they must 
be willing. OK, the subject must be lying or sitting in a comfortable position, 
relaxed, and at 
a time when things aren't going to be interrupted. Tell them the following or so 
mething 
close to it, in a peaceful, monotonous tone (not a commanding tone of voice) 


Note: Light a candle and place it somewhere where it can be easily seen. 


"Take a deep breath through your nose and hold it in for a count of 8. Now, thro 
ugh your 

mouth, exhale completely and slowly. Continued breathing long, deep, breaths thr 
ough your 

nose and exhaling through your mouth. Tense up all your muscles very tight, now, 
counting 

from ten to one, release them slowly, you will find them very relaxed. Now, look 


at the 
candle, as you look at it, with every breath and passing moment, you are feeling 
increasingly 
more and more peaceful and relaxed. The candles flame is peaceful and bright. As 
you look 
at it I will count from 100 down, as a count, your eyes will become more and mor 
e relaxed, 
getting more and more tired with each passing moment." Now, count down from 100, 
about 


every 10 numbers say "When I reach xx your eyes (or you will find your eyes) are 
becoming 

more and more tired." T them they may close their eyes whenever they feel lik 
e it. If 


the persons eyes are sti open when you get to 50 then instead of saying "your 
eyes will..." 
Say "your eyes are...". When their eyes are shut say the following. As you lie ( 


or sit) here 

with your eyes comfortably close you find yourself relaxing more and more with e 
ach 
moment and breath. The relaxation feels pleasant and blissful so, you happily gi 
ve way to 

this wonderful feeling. Imagine yourself on a cloud, resting peacefully, with a 
slight breeze 
caressing your body. A tingling sensation begins to work its way, within and wit 
hout your 

toes, it slowly moves up your feet, making them warm, heavy and relaxed. The clo 
ud is soft 
and supports your body with its soft texture, the scene is peaceful and absorbin 


g, the 
peacefulness absorbs you completely. The tingling gently and slowly moves up you 
r legs, 
relaxing them. Making them warm and heavy. The relaxation feels very good, it fe 


els so 
good to relax and let go. As the tingling continues its journey up into your sol 
ar plexus, you 
feel your inner stomach become very relaxed. Now, it moves slowly into your ches 
t, making 

your breathing relaxed as well. The feeling begins to move up your arms to your 

shoulders, 
making your arms heavy and relaxed as well. You are aware of the total relaxatio 
n you are 

now experiencing, and you give way to it. It is good and peaceful, the tingling 

now moves 
into your face and head, relaxing your jaws, neck, and facial muscles, making yo 
ur cares and 
worries float away. Away into the blue sky as you rest blissfully on the cloud. 

If they are 

not responsive or you think they (he or she) is going to sleep, then add in a". 
..always 

concentrating upon my voice, ignoring all other sounds. Even though other sounds 
exists, 


they aid you in your relaxation..." They should soon let out a sigh as if they w 
ere letting go, 

and their face should have a "woodiness" to it, becoming featureless... Now, say 
the 

following "... You now find yourself in a hallway, the hallway is peaceful and n 


ice. As I count 

from 10 to 1 you will imagine yourself walking further and further down the hall 
. When I 
reach one you will find yourself where you want to be, in another, higher state 
of conscious 


and mind. (count from ten to one)..." Do this about three or four times. Then, t 
o test if the 
subject is under hypnosis or not, say "... You feel a strange sensation in your 


(arm they write 

with) arm, the feeling begins at your fingers and slowly moves up your arm, as i 
t moves 
through your arm your arm becomes lighter and lighter, it will soon be so light 


te WILLA gia 
becoming lighter and lighter which each breath and moment..." Their fingers shou 
ld begin to 

twitch and then move up, the arm following, now my friend, you have him/her in h 
ypnosis. 

The first time you do this, while he/she is under say good things, like: "Your g 
oing to feel 

great tomorrow" or "Every day in every way you will find yourself becoming bette 
r and 

better".. Or some crap like that... The more they go under, the deeper in hypnos 
is they will 

get each time you do it. 


What to do when hypnotized 


When you have them under you must word things very carefully to get your way. Yo 
u cannot 

simply say... Take off your clothes and fuck the pillow. No, that would not real 
ly do the 
trick. You must say something like.... "you find your self at home, in your room 
and you have 
to take a shower (vividly describe their room and what's happening), you begin t 
o take off 
your clothes..." Now, it can't be that simple, you must know the persons house, 
room, and 
shower room. Then describe things vividly and tell them to act it out (they have 
to be 


deeply under to do this). I would just suggest that you experiment a while, and 
get to know 
how to do things. 


Waking up 

Waking up is very easy, just say "...as I count from 1 to 5 you wi find yourse 
lf becoming 

more and more awake, more and more lively. When you wake up you wi find yourse 
f 


completely alive, awake, and refreshed. Mentally and physically, remembering the 
pleasant 
sensation that hypnosis brings... Waking up feeling like a new born baby, reborn 
with life 
and vigor, feeling excellent. Remembering that next time you enter hypnosis it w 
ill become 


an ever increasing deeper and deeper state than before. 


You feel energy course throughout your limbs. 
You begin to breathe deeply, stirring. 


Beginning to move more and more your eyes open, bringing you up to full consciou 
S. 


You are up, up, up and awakening more and more. 


You are awake and feeling great. 


And that's it! You now know how to hypnotize yourself and someone else. 


You will learn more and more as you experiment. 


67. The Remote Informer Issue #1 by Tracker and Noman Bates 


Introduction 


Welcome to the first issue of 'The Remote Informer'! This newsletter is reader 
supported. If the readers of this newsletter do not help support it, then it wil 
l end. We 
are putting this out to help out the ones that would like to read it. If you are 
one of those 
who thinks they know everything, then don't bother reading it. This newsletter i 
s not 
anything like the future issues. The future issues will contain several sections 
, as long as 
reader input is obtained. Below is an outline overview of the sections in the fu 


ture issues. 


I/O Board (Input/Output Board) 


The I/O Board is for questions you have, that we might be able to answer or at 1 
east refer 

you to someone or something. We will be honest if we cannot help you. We will no 
t make up 

something, or to the effect, just to make it look like we answered you. There wi 
be a 
section in the I/O Board for questions we cannot answer, and then the readers wi 
have the 
opportunity to answer it. We will print anything that is reasonable in the newsl 
etter, even 

complaints if you feel like you are better than everyone. 


NewsCenter 


This section will be for news around the underworld. It will talk of busts of pe 
ople in the 

underworld and anything else that would be considered news. If you find articles 
in the 

paper, or something happens in your local area, type it up, and upload it to one 
of the boards 


listed at the end of the newsletter. Your handle will be placed in the article. 


If you do 


enter a news article, please state the date and from where you got it. 


Feature Section 


e, therefore, if 


The Feature Section will be the largest of the sections as it will be on the top 
ic that is 

featured in that issue. This will be largely reader input which will be sent in 

between 

issues. At the end of the issue at hand, it will tell the topic of the next issu 


you have something to contribute, then you will have ample time to prepare your 


article. 


Hardware/Software Review 


In this section, we wil 
related to 
the underworld. It will 
ph. 


The Tops 


ll review the good and bad points of hardware and software 


L be an extensive review, rather than just a small paragra 


This section will be the area where the top underworld BBS's, hacking programs, 


modem 
scanners, etc. will be 
ed in anyway. 


shown. This will be reader selected and will not be alter 


The topics are listed below. 


Hacking programs for 
Hacking programs for 


Tid Bits 


This will contain tips 
any 


Underworld BBS's (Hack, Phreak, Card, Anarchy, etc.) 


Hayes compatables 
1030/Xm301 modems 


Modem scanners for Hayes compatables 

Modem scanners for 1030/Xm301 modems 

Other type illegal programs 

You may add topics to the list if enough will support it. 


and helpful information sent in by the users. If you have 


information you wish to contribute, then put it in a text file and upload it to 
one of the 
BBS's listed at the end of the newsletter. Please, no long distance codes, mainf 
rame 
passwords, etc. We may add other sections as time goes by. This newsletter will 
not be put 
out on a regular basis. It will be put out when we have enough articles and info 
rmation to 

put in it. There may be up to 5 a month, but there will always be at least one a 
month. We 
would like you, the readers, to send us anything you feel would be of interest t 
o others, like 
hacking hints, methods of hacking long distance companies, companies to card fro 


We will maintain the newsletter as long as the readers support it. That is the e 


introduction, but take a look at this newsletter, as it does contain information 
that may be 
of value to you. 


Hacking Sprint: The Easy Way 


If you hack US Sprint, 950-0777 (by the way it is no longer GTE Sprint), and you 
are 

frustrated at hacking several hours only to find one or two codes, then follow t 
hese tips, 


and it wi increase your results tremendously. First, one thing that Mr. Mojo p 

roved is that 

Sprint wi not store more than one code in every hundred numbers. (ex: 98765400 
to 

98765499 may contain only one code). There may NOT be a code in that hundred, bu 

t 

there will never be more than one. Sprint's 9 digit codes are stored from 500000 
000 

through 999999999. In the beginning of Sprint's 950 port, they only had 8 digit 

codes. 

Then they started converting to 9 digit codes, storing all 8 digit codes between 
10000000 

and 49999999 and all 9 digit codes between 500000000 and 999999999. Sprint has s 


fe 
d 
Cc 
v 
t 


ince 


anceled most 8 digit codes, although there are a few left that have been denote 

as test 
odes. Occasionally, I hear of phreaks saying they have 8 digit codes, but when 
erifying 
hem, the codes were invalid. Now, where do you start? You have already narrowed 
the low 


and high numbers in half, therefore already increasing your chances of good resu 
lts by 50 

percent. The next step is to find a good prefix to hack. By the way, a prefix, i 
n hacking 

terms, is the first digits in a code that can be any length except the same numb 
er of digits 

the code is. (ex: 123456789 is a code. That means 1, 12, 123, 1234, 12345, 12345 
6, 

1234567, and 12345678 are prefixes) The way you find a good prefix to hack is to 


tax ca oO 


1 
d 


C 


manually 

nter a code prefix. If when you enter the code prefix and a valid destination n 
mber and 

ou do not hear the ringing of the recording telling you that the code is invali 
until near 

he end of the number, then you know the prefix is valid. Here is a chart to fol 
ow when 

oing this: 


ode - Destination Range good codes exist 


1 


1 


1 


1 


23456789 - 6192R 123400000 - 123499999 
23456789 - 619267R 123450000 - 123459999 
23456789 - 61926702R 123456000 - 123456999 
23456789 - 6192670293R 123456700 - 123456799 


( 


T 


R - Denotes when ring for recording starts) 


o prove this true, I ran a test using OmniHack 1.3p, written by Jolly Joe. In t 


his test I 

found a prefix where the last 3 digits were all I had to hack. I tested each hun 
dred of the 
6 digit prefix finding that all but 4 had the ring start after the fourth digit 
was dialed in 

the destination number. The other four did not ring until I had finished the ent 
ire code. I 
set OmniHack to hack the prefix + 00 until prefix + 99. (ex: xxxxxxy00 to xxxxxx 
y99: 

where y is one of the four numbers that the ring did not start until the dialing 
was 

completed.) Using this method, I found four codes in a total of 241 attempts usi 
ng 

ascending hacking (AKA: Sequential). Below you will see a record of my hack: 


Range of hackCodes foundTriesxxxxxx300 - xxxxxx399xxxxxx35050xxxxxx500 - 
XXXXXX599xxXxXxxx56868xxXxXxxx600 - xxxxxx699xxxxxx64646xxxxxx800 - 
XXXXXxX8 99xxxxxx87777Totals4 codes241 


As you see, these methods work. Follow these guidelines and tips and you should 
have an 
increase in production of codes in the future hacking Sprint. Also, if you have 
any 

hints/tips you think others could benefit from, then type them up and upload the 
m to one of 

the boards at the end of the newsletter. 


Rumors: Why Spread Them? 


Do you ever get tired of hearing rumors? You know, someone gets an urge to impre 
ss 

others, so they create a rumor that some long distance company is now using trac 
ing 

equipment. Why start rumors? It only scares others out of phreaking, and then ma 
kes you, 
the person who started the rumor, look like Mr. Big. This article is short, but 

it should 

make you aware of the rumors that people spread for personal gain. The best thin 
g to do is 

to denote them as a rumor starter and then leave it at that. You should not rag 

on them 

constantly, since if the other users cannot determine if it is fact or rumor, th 
en they 

should suffer the consequences. 


H 


he New Sprint FON Calling Cards 


US Sprint has opened up a new long distance network called the Fiber Optic Netwo 
rk 

(FON), in which subscribers are given calling cards. These calling cards are 14 
digits, and 
though, seem randomly generated, they are actually encrypted. The rumors floatin 
g around 

about people getting caught using the Sprint FON calling cards are fact, not rum 
ors. The 

reason people are getting caught is that they confuse the FON calling cards with 
the local 

950 port authorization codes. If you will remember, you never use AT&T calling c 
ards from 
you home phone. It has ANI capability, which is not tracing, but rather the orig 
inating 
phone number is placed on the bill as soon as the call is completed. They know y 
our phone 
number when you call the 800 access port, but they do not record it until your c 
all is 
completed. Also, through several of my hacks, I came up with some interesting in 
formation 
surrounding the new Sprint network. They are listed below. 


800-877-0000 - This number is for information on US Sprint's 800 calling card se 
rvice. I 
have not played around with it, but I believe it is for trouble or help with the 
FON calling 

cards. I am not sure if it is for subscribing to the FON network. 


800-877-0002 - You hear a short tone, then nothing. 
800-877-0003 - US Sprint Alpha Test Channel #1 
800-877-(0004-0999) - When you call these numbers, you get a recording saying: " 


Welcome 
to US Sprint's 1 plus service." When the recording stops, if you hit the pound k 


ey (#) you 
will get the calling card dial tone. 


Other related Sprint numbers 


800-521-4949 - This is the number that you subscribe to US Sprint with. You may 
also 

subscribe to the FON network on this number. It will take 4 to 5 weeks for your 
calling 

card to arrive. 


10777 - This is US Sprint's equal access number. When you dial this number, you 
then dia 
the number you are calling, and it will be billed through US Sprint, and you wil 
receive their 

long distance line for that call. Note that you will be billed for calls made th 
rough equal 
access. Do not mistake it to be a method of phreaking, unless used from a remote 
location. 
If you are in US Sprint's 1+ service then call 1+700-555-1414, which will tell y 
ou which long 
distance company you are using. When you hear: "Thank you for choosing US Sprint 
"s 1 plus 
service," hit the pound key (#), and then you will get the US Sprint dial tone. 
This however 
is just the same as if you are calling from your home phone if you dial direct, 
so you would 
be billed for calls made through that, but there are ways to use this to your ad 
vantage as in 

using equal access through a PBX. 


Automatic Number Identification (ANI) 


The true definition for Automatic Number Identification has not been widely know 


n to 


tion 


method of 


many. Automatic Number Identification, (AKA: ANI), is the process of the destina 
number knowing the originating number, which is where you are calling from. The 


achieving this is to send the phone number that you are calling from in coded fo 


rm ahead of 


ANI Method 


Dial: 267-0293 


Sent: ********2 670293 


the destination number. Below is an example of this. 


* — Denotes the originating number which is coded and sent before the 


number 


As you noticed there are 8 digits in 
I believe, it 


the coded number. This is because, at least 


is stored in a binary-like form. Automatic Number Identification means a limited 


future in 


phreaking. ANI does not threaten phreaking very much yet, but it will in the nea 


r future. A 


new switching system will soon be installed in most cities that are covered by E 


11l be 


Electronic Switching System, now. The system will have ANI capabilities which wi 


supplied to the owners of phone lines as an added extra. The owner's phone will 


have an 


LED read-out that will show the phone number of the people that call you. You wi 


1l be able 


ting stages 


to block some numbers, so that people cannot call you. This system is in the tes 


currently, but will soon be installed across most of the country. As you see, th 


is will end a 


large part of phreaking, until we, the phreakers, can come up with an alternativ 


e. As I have 


been told by several, usually reliable, people, this system is called ISS, which 


I am not sure 
of the meaning of this, and is being 
tts lines set 
up by AT&T support ANI. The equipmen 
does 
not costs as much as you would expec 

matter 
what you have been told. The 950 por 

based, this 


tested currently in Rhode Island. 800 in-wa 
t to decode an ANI coded origination number 
t. 950 ports do not offer ANI capability, no 


ts will only give the city in which they are 


usually being the largest in the sta 


te, sometimes the capitol. One last thing th 


at I should 

tell you is that ANI is not related to tracing. Tracing can be done on any numbe 
r whether 
local, 950, etc. One way around this, especially when dialing Alliance TeleConfe 
rencing, is to 

dial through several extenders or ports. ANI will only cover the number that is 
calling it, 

and if you call through a number that does not support ANI, then your number wil 
l never be 

known. 


68. Jackpotting ATM Machines by The Jolly Roger 


JACKPOTTING was done rather successfully a while back in (you guessed it) New Yo 
rk. 
What the culprits did was sever (actually cross over) the line between the ATM a 
nd the 

host. Insert a microcomputer between the ATM and the host. Insert a fraudulent c 
ard into 

the ATM. (By card I mean cash card, not hardware.) What the ATM did was: send a 

signal 

to the host, saying "Hey! Can I give this guy money, or is he broke, or is his c 
ard invalid?" 

What the microcomputer did was: intercept the signal from the host, discard it, 

send 

"there's no one using the ATM" signal. What the host did was: get the "no one us 
ing" signal, 


send back "okay, then for God's sake don't spit out any money!" signal to ATM. W 
hat the 

microcomputer did was intercept the signal (again), throw it away (again), send 
"Wow! That 

guy is like TOO rich! Give him as much money as he wants. In fact, he's so loade 
d, give him 

ALL the cash we have! He is really a valued customer." signal. What the ATM did: 
what 

else? Obediently dispense cash till the cows came home (or very nearly so). What 
the crooks 


got was well in excess of $120,000 (for one weekend's work), and several years w 
hen they 

were caught. This story was used at a CRYPTOGRAPHY conference I attended a while 
ago 


to demonstrate the need for better information security. The lines between ATM's 
& their 

hosts are usually 'weak' in the sense that the information transmitted on them i 
s generally 

not encrypted in any way. One of the ways that JACKPOTTING can be defeated is to 


encrypt the information passing between the ATM and the host. As long as the key 
cannot 

be determined from the ciphertext, the transmission (and hence the transaction) 
is secure. 

A more believable, technically accurate story might concern a person who uses a 
computer 

between the ATM and the host to determine the key before actually fooling the ho 
st. As 

everyone knows, people find cryptanalysis a very exciting and engrossing subject 
..don't 

they? (Hee-Hee) 


LEs a | 
|ATM| micro |Host| 


|_| ->>-| | ->> 


The B of A ATM's are connected through dedicated lines to a host computer as the 
Bishop 

said. However, for maintenance purposes, there is at least one separate dial-up 
line also 

going to that same host computer. This guy basically BS'ed his way over the phon 
e till he 

found someone stupid enough to give him the number. After finding that, he had h 
as Apple 

hack at the code. Simple. 


Next, he had a friend go to an ATM with any B of A ATM card. He stayed at home w 
ith the 
Apple connected to the host. When his friend inserted the card, the host display 


ed it. The 

guy with the Apple modified the status & number of the card directly in the host 
"s memory. 

He turned the card into a security card, used for testing purposes. At that poin 
t, the ATM 

did whatever it's operator told it to do. 


The next day, he went into the bank with the $2000 he received, talked to the ma 
nager and 

told him every detail of what he'd done. The manager gave him his business card 
and told 

him that he had a job waiting for him when he got out of school. 


Now, B of A has been warned, they might have changed the system. On the other ha 
nd, it'd 

be awful expensive to do that over the whole country when only a handful of peop 
le have the 

resources and even less have the intelligence to duplicate the feat. Who knows? 


69. Jug Bomb by The Jolly Roger 


Take a glass jug, and put 3 to 4 drops of gasoline into it. Then put the cap on, 
and swish the 

gas around so the inner surface of the jug is coated. Then add a few drops of po 
tassium 


permanganate solution into it and cap it. To blow it up, either throw it at some 
thing, or roll 
it at something. 


70. Fun at K-Mart by The Jolly Roger 


Well, first off, one must realize the importance of K-Marts in society today. Fi 
rst off, K- 

Marts provide things cheaper to those who can't afford to shop at higher quality 
stores. 


Although, all I ever see in there is minorities and Senior Citizens, and the poo 
r people in our 
city. Personally, I wouldn't be caught dead in there. But, once, I did. You see, 


once, after 
The Moon Roach and Havoc Chaos (Dear friends of mine) and I were exploring such 
fun 

things as rooftops, we came along a K-Mart. Amused, and cold for that matter, we 


wandered in. The Tension mounts. As we walked up to the entrance, we were nearly 


attacked by Youth Groups selling cheap cookies, and wheelchair sticken people se 
lling 
American Flags. After laughing at these people, we entered. This is where the re 
al fun 
begins... First, we wandered around the store, and turned on all the blue lights 
we could find. 

That really distracts and confuses the attendents...Fun to do... The first neat 
thing, is to go 

to the section of the store where they sell computers. Darkness engulfs the eart 
h the day 

they find Apple Computers being sold there. Instead, lesser computers like the l 
aughable 

C-64 can be found there...Turn it on, and make sure nobody's looking...Then, onc 
e in Basic, 


LV DG ear 


]10 PRINT "Fuck the world! Anarchy Rules!" (or something to that effect.) 


]20 GOTO 10 and walk away. 


Also, set the sample radios in the store to a satanic rock station, and turn the 
radio off. 

Then, set the alarm for two minutes ahead of the time displayed there. Turn the 
volume up 
all the way, and walk away. After about two minutes, you will see the clerk feeb 
ly attempt 

to turn the radio down or off. It's really neat to set ten or more radios to dif 
ferent 

stations, and walk away. One of my favorite things to do, is to get onto the int 


ercom system 


of the store. Easier typed then done. 


u say 


First, check out the garden department. Yo 


there's no attendent there? Good. Sneak carefully over to the phone behind the c 


heap 


counter there, and pick it up. Dial the number corresponding to the item that sa 
ys 'PAGE'... 
And talk. You will note that your voice will echo all over the bowels of K-Mart. 


I would 


suggest announcing something on the lines of: 


71. Mace Substitute by The Jolly Roger 


3 parts Al 


-or- 


lcohol 


« part Iodine 
« part Sal 


t 


3 parts Alcohol 
1 part Iodized Salt (Mortons) 


"Anarchy rules!!" 


It's not actual mace, but it does a damn good job on the eyes... 


Ts 


MAR 


How to grow Marijuana by The Jolly Roger 


TIJUANA 


Marijuana is a deciduous plant which grows from seeds. The fibrous section of th 


e p 


lant was 


(has been replaced by synthetics) used to make rope. The flowering tops, leaves, 
seeds, and 


res 


in of the plant is used by just about everyone to get HIGH. Normally, the veg 
etable 


parts of the plant are smoked to produce this "high," but they can also be eaten 
. The active 


ingredient in marijuana resin is THC (Tetahydrocannabinol). Marijuana contains f 
rom 13-45% 

THC (4% must be considered GOOD dope). Marijuana grows wild in many parts of the 
world, 

and is cultivated in Mexico, Vietnam, Africa, Nepal, India, South America, etc. 
The 

marijuana sold in the United States comes primarily from, yes, the United States 

It is 

estimated that at least 50% of the grass on the streets in America is homegrown. 
The next 

largest bunch comes across the borders from Mexico, with smaller amounts filteri 
ng in 

from Panama, occasionally South America, and occasionally, Africa. Hashish is th 
e pure resin 

of the marijuana plant, which is scraped from the flowering tops of the plant an 


umped 


together. Ganja is the ground-up tops of the finest plants. (It is also the name 
given to any 


sor 


t of marijuana in Jamaica.) Marijuana will deteriorate in about two years if 


exposed to 


light, air or heat. It should always be stored in cool places. Grass prices in t 
he United 

States are a direct reflection of the laws of supply and demand (and you thought 
that high 

school economics would never be useful). A series of large border busts, a short 
growing 


season, a bad crop, any number of things can drive the price of marijuana up. De 


mand still 


seems to be on the increase in the US, so prices seldom fall below last year's 1 


evel. Each 


year a small seasonal drought occurs, as last year's supply runs low, and next y 


ear's crop is 

not up yet. Prices usually rise about 20%-75% during this time and then fall bac 
k to 

"normal." Unquestionably, a large shortage of grass causes a percentage of smoke 


rs to turn 


to harder drugs instead. For this reason, no grass control program can ever be b 
eneficial or 
"successful." 


GROW IT 


There is one surefire way of avoiding high prices and the grass DT's: Grow your 
own. This is 

not as difficult as some "authorities" on the subject would make you believe. Ma 
rijuana is a 
weed, and a fairly vivacious one at that, and it will grow almost in spite of yo 
u. 


OUTDOORS 


Contrary to popular belief, grass grows well in many place on the North American 
continent. 
It will flourish even if the temperature does not raise above 75@. The plants do 
need a 

minimum of eight hours of sunlight per day and should be planted in late April/e 
arly May, 

BUT DEFINITELY, after the last frost of the year. Growing an outdoor, or "au nat 
urel", 
crop has been the favored method over the years, because grass seems to grow bet 


without as much attention when in its natural habitat. Of course, an outdoors se 


requires special precautions not encountered with an indoors crop; you must be a 
ble to avoid 
detection, both from law enforcement freaks and common freaks, both of whom will 
take 
your weed and probably use it. Of course, one will also arrest you. You must als 
o have access 


to the area to prepare the soil and harvest the crop. There are two schools of t 

hought 

about starting the seeds. One says you should start the seedlings for about ten 
days in an 

indoor starter box (see the indoor section) and then transplant. The other theor 
y is that 
you should just start them in the correct location. Fewer plants will come up wi 
th this 

method, but there is no shock of transplant to kill some of the seedlings halfwa 
y through. 

The soil should be prepared for the little devils by turning it over a couple of 
times and 

adding about one cup of hydrated lime per square yard of soil anda little bit ( 
not too much, 

now) of good water soluble nitrogen fertilizer. The soil should now be watered s 
everal times 
and left to sit about one week. The plants should be planted at least three feet 
apart, 

getting too greedy and stacking them too close will result in stunted plants. Th 
e plants like 

some water during their growing season, BUT 
e around 

the roots, as too much water will rot the root system. Grass grows well in corn 
or hops, and 

these plants will help provide some camouflage. It does not grow well with rye, 
spinach, or 

pepperweed. It is probably a good idea to plant in many small, broken patches, a 
s people 

tend to notice patterns. 


not too much. This is especially tru 


GENERAL GROWING INFO 


Both the male and he female plant produce THC resin, although the male is not as 
strong as 

the female. In a good crop, the male will still be plenty smokable and should no 

t be thrown 

away under any circumstances. Marijuana can reach a height of twenty feet (or wo 

uld you 

rather wish on a star) and obtain a diameter of 4« inches. If normal, it has as 
ex ratio of 

about 1:1, but this can be altered in several ways. The male plant dies in the 1 
2th week of 

growing, the female will live another 3-5 weeks to produce her younguns. Females 
can weigh 

twice as much as males when they are mature. Marijuana soil should compact when 

you 

squeeze it, but should also break apart with a small pressure and absorb water w 

ell. A nice 

test for either indoor or outdoor growing is to add a bunch of worms to the soil 
, if they live 

and hang around, it is good soil, but if they don't, well, change it. Worms also 
help keep the 

soil loose enough for the plants to grow well. 


SEEDS 


To get good grass, you should start with the right seeds. A nice starting point 

is to save the 

seeds form the best batch you have consumed. The seeds should be virile, that is 
, they 

should not be gray and shriveled up, but green, meaty, and healthy appearing. A 

nice test is 

to drop the seeds on a hot frying pan. If they "CRACK," they are probably good f 
or planting 

purposes. The seeds should be soaked in distilled water overnight before plantin 
g. BE SURE 
to plant in the ground with the pointy end UP. Plant about «" deep. Healthy seed 
s will sprout 

in about five days. 


SPROUTING 


The best all around sprouting method is probably to make a sprouting box (as sol 
din 

nurseries) with a slated bottom or use paper cups with holes punched in the bott 
oms. The 
sprouting soil should be a mixture of humus, soil, and five sand with a bit of o 
rganic 

fertilizer and water mixed in about one week before planting. When ready to tran 
splant, you 

must be sure and leave a ball of soil around the roots of each plant. This whole 
ba is 

dropped into a baseball-sized hold in the permanent soil. If you are growing/tra 
nsplanting 

indoors, you should use a green safe light (purchased at nurseries) during the t 
ransplanting 


operation. If you are transplanting outdoors, you should time it about two hours 
before 

sunset to avoid damage to the plant. Always wear cotton gloves when handling the 
young 
plants. After the plants are set in the hole, you should water them. It is also 
a good idea to 
use a commercial transplant chemical (also purchased at nurseries) to help then 
overcome 

the shock. 


INDOOR GROWING 


Indoor growing has many advantages, besides the apparent fact that it is much ha 
rder to 
have your crop "found," you can control the ambient conditions just exactly as y 
ou want 
them and get a guaranteed "good" plant. Plants grown indoors will not appear the 
same as 
their outdoor cousins. They will be scrawnier appearing with a weak stems and ma 
y even 
require you to tie them to a growing post to remain upright, BUT THEY WILL HAVE 
AS 
MUCH OR MORE RESIN! If growing in a room, you should put tar paper on the floors 
and 
then buy sterilized bags of soil form a nursery. You will need about one cubic f 
oot of soil 
for each plant. The plants will need about 150 mL. of water per plant/per week. 
They will 
also need fresh air, so the room must be ventilated. (However, the fresh air sho 
uld contain 
NO TOBACCO smoke.) At least eight hours of light a day must be provided. As you 
increase 
the light, the plants grow faster and show more females/less males. Sixteen hour 
s of light 
per day seems to be the best combination, beyond this makes little or no appreci 
able 
difference in the plant quality. Another idea is to interrupt the night cycle wi 
th about one 
hour of light. This gives you more females. The walls of your growing room shoul 
d be painted 
white or covered with aluminum foil to reflect the light. The lights themselves 
can be either 
bulbs of fluorescent. Figure about 75 watts per plant or one plant per two feet 


fluorescent tube. The fluorescents are the best, but do not use "cool white" typ 
es. The 
light sources should be an average of twenty inches from the plant and NEVER clo 
ser than 

14 inches. They may be mounted on a rack and moved every few days as the plants 
grow. The 

very best light sources are those made by Sylvania and others especially for gro 
wing plants 

(such as the "gro lux" types). 


HARVESTING AND DRYING 


The male plants will be taller and have about five green or yellow sepals, which 


wi split open 
to fertilize the female plant with pollen. The female plant is shorter and has a 
sma 
pistillate flower, which really doesn't look like a flower at all but rather as 


mall bunch of 
leaves in a cluster. If you 
k the males 


don't want any seeds, just good dope, you should pic 


before they shed their pollen as the female will use some of her resin to make t 


he seeds. 
After another three to five 
gin to 


iddle Eastern 

countries, farmers reported! 
e little 

devils collect the grass pol 
fair dosage of 


weeks, after the males are gone, the females will be 


wither and die (from loneliness?), this is the time to pick. In some nefarious M 


ly put their beehives next to fields of marijuana. Th 


llen for their honey, which is supposed to contain a 


THC. The honey is then enjoyed by conventional methods or made into ambrosia. If 


you want 


seeds - let the males shed his pollen then pick him. Let the female go another m 


onth and 


lished by 


pick her. To cure the plants, they must be dried. On large crops, this is accomp 


constructing a drying box or drying room. You must have a heat source (such as a 


n electric 
heater) which will make the 
to carry 


box/room each 130ø. The box/room must be ventilated 


off the water-vapor-laden air and replace it with fresh. A good box can be const 


ructed 


from an orange crate with fiberglass insulated walls, vents in the tops, and scr 


een shelves 


to hold the leaves. There must be a baffle between the 
A quick 


Cs 
cu 


re 


leaves and the heat sourc 


for smaller amounts is to: cut the plant at the soil level and wrap it ina 


cloth so as not 


to loose any leaves. Take out any seeds by hand 


on 
sh 
Ë 


In 


nother ten 


a cookie 
eet or aluminum foil and put them in the middi 
on "broil." 

a few seconds, the leaves will smoke and curl 


es 


seconds before you take them out. 


E 


TO INCREASE THE GOOD STUFF 


There are several tricks to increase the number of females, 


plants: 


You can 
on 
to about 14 hours, but the plants will not be as big. You should gradual] 


en t 


cycle until you reach fourteen hours. You can stop any watering as the pl 


g 


pl 


n 


an 


the light 


he light 


to bake 


t at the spot 


where it joins the plant, and a new flower will form in a couple of weeks. Thi 


can be 


repeated two or three times to get severa 


If the plants are sprayed with Ethrel early in their growing stage, they will 


and store. Place all the leaves 


times more flowers than usual. 


oduce almost 


al 


fema 


S 


weeks. 
get and 


e plants. This usually speeds up the flowering also, it may happen 
ittle as two 
You can employ a growth changer called colchicine. This is a bit hard to 


in 


le shelf of the oven, which is se 


up, stir them around and give a 


or the THC content o 
make the plants mature in 36 days if you are in a hurry, by cutting back 
ly short 
lants be 
the resin rise to the flowers. This will increase the resin a bit. You can use a 


sunlamp on the 
ts as they begin to develop flower stalks. You can snip off the flower, ri 


gh 


S 


pr 


a 


expensive. (Should be ordered through a lab of some sort and costs about $35 a g 


ram.) To 
use the colchicine, you shoul 
er with about 


= 


ld prepare your presoaking solution of distilled wat 


0.10 per cent colchicine. This will cause many of the seeds to die and not germi 


nate, but the 


ones that do come up will be polyploid plants. 


g 
runs 
S 
g 


ere is that co 


he 


tween such 
ins as "gold" and normal grass, and yours wi 


first 


This is the accepted difference b 


chicine is a poison in larger quantities and may be poisonous 


ity. However, the Medical Index shows colch 


ities to 
le for treatment if various ailments. Although these quantities are small 


hey would 


icine being given in very smal 


eration of plants. Bill Frake, author of CONNOISSEUR'S HANDBOOK OF MARIJUANA 
a very complete colchicine treatment down and warns against smoking the fir 


1 


T 


11 DEFINITELY be superweed. The 


in 


eration plants (all succeeding generations will also be polyploid) because of 
his poisonous 
qua 
uant 
peop] 


q 


t 


appear to be larger than any you could receive form smoking a seed-treated plant 
It would 

be a good idea to buy a copy of CONNOISSEUR'S, if you are planning to attempt th 

is, and 

read Mr. Drake's complete instructions. Another still-experimental process to in 

crease the 

resin it to pinch off the leaf tips as soon as they appear from the time the pla 

nt is in the 

seedling stage on through its entire life-span. This produces a distorted, wreck 

ed-lLlooking 

plant which would be very difficult to recognize as marijuana. Of course, there 

is less 

substance to this plant, but such wrecked creatures have been known to produce s 

o much 

resin that it crystallizes a strong hash all over the surface of the plant - mig 

ht be wise to 

try it on a plant or two and see what happens. 


PLANT PROBLEM CHART 


Always check the overall environmental conditions prior to passing judgment - so 
il around 7 
pH or slightly less - plenty of water, light, fresh air, loose soil, no water st 
anding in pools. 


SYMPTOMPROBABLY PROBLEM/CURELarger leaves turning yellow - smaller leaves still 
green.Nitrogen deficiency - add nitrate of soda or organic fertilizer.Older leav 
es will curl at 


edges, turn dark, possibly with a purple cast.Phosphorous deficiency - add comme 
rcial 
phosphate.Mature leaves develop a yellowish cast to least venial areas.Magnesium 
deficiency 
- add commercial fertilizer with a magnesium content.Mature leaves turn yellow a 
nd then 
become spotted with edge areas turning dark gray.Potassium deficiency - add muri 
ate of 
potash.Cracked stems, no healthy support tissue.Boron deficiency - add any plant 
food 
containing boron.Small wrinkled leaves with yellowish vein systems.Zinc deficien 
cy - add 
commercial plant food containing zinc.Young leaves become deformed, possibly 
yellowing.Molybdenum deficiency - use any plant food with a bit of molybdenum in 
Lt: 


O 


EXTRA SECTION: BAD WEED/GOOD WEED 


Can you turn bad weed into good weed? Surprisingly enough, the answer to this of 
ten-asked 

inguiry is, yes! Like most other things in life, the amount of good you are goin 
g to do relates 
directly to how much effort you are going to put into it. There are no instant, 
supermarket 
products which you can spray on Kansas catnip and have wonderweed, but there are 
a 
number of simplified, inexpensive processes (Gee, Mr. Wizard!) which will enhanc 
e mediocre 
grass somewhat, and there are a couple of fairly involved processes which will d 
o up even 

almost-parsley weed into something worth writing home about. 


EASES 

Place the dope in a container which allows air to enter in a restricted fashion 
(such as a can 

with nail holes punched in its lid) and add a bunch of dry ice, and the place th 


e whole 
shebang in the freezer for a few days. This process will add a certain amount of 


potency to the product, however, this only works with dry ice, if you use normal 


everyday freezer ice, you will end up with a soggy mess... 


Take a quantity of grass and dampen it, place in a baggy or another socially acc 
ee and store it in a dark, dampish place for a couple of weeks (burying 
ieee work). The grass will develop a mold which tastes a bit harsh, a and bu 
Hay Bit funny, but does increase the potency. 


Expose the grass to the high intensity light of a sunlamp for a full day or so. 


Personally, I 

don't feel that this is worth the effort, bu 
end's 

money for this brick of super-Colombian, rig 
sh, 

and it turns out to be Missouri weed, and yo 
before 

the people arrive for their shares, well, yo 


t if you just spent $400 of your fri 


ht-from-the-President's-personal-sta 


u're packing your bags to leave town 


u might at least try it. Can't hurt. 


Take the undesirable portions of our stash (stems, seeds, weak weed, worms, etc. 


) and place 


them in a covered pot, with enough rubbing alcohol to cover everything. Now 
CAREFULLY boil the mixture on an ELECTRIC stove or lab burner. DO NOT USE GAS - 
the alcohol is too flammable. After 45 minutes of heat, remove the pot and strai 


n the 


solids out, SAVING THE ALCOHOL. Now, repeat the process with the same residuals, 


but fresh alcohol. When the second boil is over, remove the solids again, combin 


e the 


syrupy 


simply 


prove 
upon. 


two quantities of alcohol and reboil until you have a syrupy mixture. Now, this 
mixture will contain much of the THC formerly hidden in the stems and such. One 


takes this syrup the thoroughly combines it with the grass that one wishes to im 


SPECIAL SECTION ON RELATED SUBJECT MARYGIN 


Marygin is an anagram of the words marijuana and gin, as in Eli Whitney. It is a 
plastic 

tumbler which acts much like a commercial cotton gin. One takes about one ounce 
of an herb 
and breaks it up. This is then placed in the Marygin and the protruding knob is 
rotated. This 

action turns the internal wheel, which separates the grass from the debris (seed 
s, stems). 

It does not pulverize the grass as screens have a habit of doing and is easily w 
ashable. 


Marygin is available from: 


P.O. Box 5827 
Tuscon, Arizona 85703 


$5.00 


GRASS 
Edmund Scientific Company 
555 Edscorp Building 


Barrington, New Jersy 08007 


Free Catalog is a wonder of good things for the potential grass grower. They hav 
e an 

electric thermostat greenhouse for starting plants. Lights which approximate the 
true color 

balance of the sun and are probably the most beneficial types available: 40 watt 
, 48 inch 

Indoor sun bulb, 75 or 150 watt And, they have a natural growth regulator for pl 
ants 

(Gibberellin) which can change height, speed growth, and maturity, promote bloss 
oming, etc. 

Each plant reacts differently to treatment with Gibberellin...there's no fun lik 
e 

experimenting. 


SUGGESTED READING 


THE CONNOISSEUR'S HANDBOOK OF MARIJUANA, Bill Drake 


Straight Arrow Publishing - $3«0 


625 Third Street 


San Francisco, California 


FLASH 
P.O.Box 16098 


San Fransicso, California 94116 


Stocks a series of pamphlets on grass, dope manufacture, cooking. Includes the M 
ary Jane 
Superweed series. 


73. Match Head Bomb by The Jolly Roger 


Simple safety match heads in a pipe, capped at both ends, make a devastating bom 

b. It is 

set off with a regular fuse. A plastic baggy is put into the pipe before the hea 
ds go in to 

prevent detonation by contact with the metal. Cutting enough match heads to fill 
the pipe 


can be tedious work for one but an evening's fun for the family if you can drag 
them away 
from the TV. 


74, How To Terrorize McDonalds by The Jolly Roger 


Now, although McDonalds is famous for it's advertising and making the whole worl 
d think 
that the BigMac is the best thing to come along since sliced bread (buns?), each 
little 
restaurant is as amateur and simple as a new-found business. Not only are all th 
e employees 
rather inexperienced at what they're supposed to do, but they will just loose al 
L control 
when an emergency occurs....here we go!!! First, get a few friends (4 is good... 
I'll get to this 
later) and enter the McDonalds restaurant, talking loudly and reeking of some st 
range smell 
that automatically makes the old couple sitting by the door leave. If one of tho 
se pimply- 
faced goons is wiping the floor, then track some crap all over it (you could pre 
tend to slip 
and break your head, but you might actually do so). Next, before you get the foo 
d, finda 
table. Start yelling and releasing some strange body odor so anybody would leave 
their table 
and walk out the door. Sit two friends there, and go up to the counter with anot 
her. Find a 
place where the line is short, or if the line is long say "I only wanna buy a co 
ke." and you get 
moved up. Now, you get to do the ordering ...heh heh heh. Somebody always must w 
ant a 
plain hamburger with absolutely nothing on it (this takes extra time to make, an 
d drives the 
little hamburger-makers insane)..order a 9-pack of chicken McNuggets...no, a 20 
pack...no, 
three 6 packs...wait...go back to the table and ask who wants what. Your other f 
riend waits 
by the counter and makes a pass at the female clerk. Get back to the thing and o 
rder three 
6-packs of chicken etc....now she says "What kind of sauce would you like?". Of 
course, say 
that you all want barbecue sauce one of your friends wants 2 (only if there are 
only 2 
containers of barbecue sauce left). Then they hafta go into the storeroom and op 
en up 
another box. Finally, the drinks...somebody wants coke, somebody root beer, and 
somebody 
diet coke. After these are delivered, bring them back and say "I didn't order a 
diet coke! I 
ordered a sprite!" This gets them mad; better yet, turn down something terrible 
that 
nobody wants to drink, so they hafta throw the drink away; they can't sell it. A 


fter all the 

food(?) is handed to you, you must never have enoug 
l be so 

angry and confused that she'll let you get away wit 
r is your 

friend asking her "If you let us go, I'll go out wi 
e fone number). 

Now, back to your table. But first, somebody likes 
ty (too 

much) of napkins. Oh, and somebody likes forks and 
king the 


s!!" As loud 


h money to pay. The clerk wil 


h it (another influence on he 


th you." and giving her a fak 


ketchup and mustard. And plen 


knives, so always end up brea 


as they can. That'll worry the entire restaurant. Proceed to sit down. So, you a 


re sitting in 


the smoking section (by accident) eh? Well, while one of the tobacco-breathers i 


sn't 
looking, put a sign from the other side of the room 
nd he'll 

hafta move...then he goes into the real non-smoking 
He then 

thinks that no smoking is allowed in the restaurant 
pouring rain) 


saying "Do not smoke here" a 
section, and gets yelled at. 


, so he eats outside (in the 


after your meal is finished (and quite a few splattered-opened ketchup packets a 


re all over 


your table), try to leave. But oops! Somebody has to do his duty in the men's ro 


om. As he 


goes there, he sticks an uneaten hamburger (would you dare to eat one of their 


hamburgers?) Inside the toilet, flushes it a while, 
athroom. Oops! 


until it runs all over the b 


Send a pimply-faced teenager to clean it up. (He won't know that brown thing is 


hamburger, and he'll get sick. Wheee!) As you leave the restaurant, looking back 
at your 

uncleaned table, somebody must remember that they left their chocolate shake the 
re! The 
one that's almost full!!!! He takes it then says "This tastes like crap!", Then 
he takes off the 
id and throws it into the garbage can...oops! He missed, and now the same poor 
soul who's 
cleaning up the bathroom now hasta clean up chocolate shake. Then leave the join 
t, 

reversing the "Yes, we're open" sign (as a reminder of your visit) There you hav 
e it! You 

have just put all of McDonalds into complete mayhem. And since there is no penal 
ty for 
littering in a restaurant, bugging people in a public eatery (or throw-upery, in 
this case) you 
get off scot-free. Wasn't that fun? 


j= 


75. "Mentor's Last Words" by +++The Mentor+++4 


The following file is being reprinted in honor and sympathy for the many phreaks 
and 
hackers that have been busted recently by the Secret Service. 


The Conscience of a Hacker 


Another one got caught today, it's all over the papers. “Teenager Arrested in Co 
mputer 
Crime Scandal", "Hacker Arrested after Bank Tampering"... Damn kids. They're all 
alike. 
But did you, in your three-piece psychology and 1950's technobrain, ever take a 
look behind 
the eyes of the hacker? Did you ever wonder what made him tick, what forces shap 
ed him, 
w 
b 
s 


hat may have molded him? I am a hacker, enter my world... Mine is a world that 
egins with 
chool... I'm smarter than most of the other kids, this crap they teach us bores 
me... Damn 
underachiever. They're all alike. I'm in junior high or high school. I've listen 
ed to teachers 


explain for the fifteenth time how to reduce a fraction. I understand it. "No, M 
s. Smith, I 

didn't show my work. I did it in my head..." Damn kid. Probably copied it. They' 
re all alike. I 


made a discovery today. I found a computer. Wait a second, this is cool. It does 
what I 
want it to. If it makes a mistake, it's because I screwed it up. Not because it 
doesn't like 
me or feels threatened by me or thinks I'm a smart ass or doesn't like teaching 
and 
shouldn't be here...damn kid. All he does is play games. They're all alike. And 


then it 

happened. A door opened to a world. Rushing through the phone line like heroin t 
hrough an 
addict's veins, an electronic pulse is sent out, a refuge from the day-to-day in 
competencies 
is sought... a board is found. "This is it... this is where I belong..." I know 
everyone here... 

even if I've never met them, never talked to them, may never hear from them agai 
Tosa I 


know you all... Damn kid. Tying up the phone line again. They're all alike... Yo 

u bet your ass 

we're all alike... we've been spoon-fed baby food at school when we hungered for 
steak... 


the bits of meat that you did let slip through were pre-chewed and tasteless. We 
've been 

dominated by sadists, or ignored by the apathetic. The few that had something to 
teach 

found us willing pupils, but those few are like drops of water in the desert. 


This is our world now... the world of the electron and the switch, the beauty o 
f the 


baud. We make use of a service already existing without paying for what could be 


dirt- 

cheap if it wasn't run by profiteering gluttons, and you call us criminals. We e 
xplore... and 

you call us criminals. We seek after knowledge... and you call us criminals. We 
exist without 

skin color, without nationality, without religious bias... and you call us crimi 
nals. You build 


76. 


The Myth of the 2600hz Detector by The Jolly Roger 


Defeating the kick-back detector 


As mentioned in my previous note, kick-back detection can be a serious nuisance 


to anyone 


interested in gaining control of a trunk line. The easiest way to by-pass this d 


etection 


circuitry is not really by-passing it at all, it is just letting the kick-back g 
et detected on 
some other line. This other line is your local MCI, sprint, or other long distan 


ce carrier 


(except AT&T). The only catch is that the service you use must not disconnect th 


e line 


when you hit the 2600hz tone. This is how you do it: call up your local extender 


r 


ut in the 


code, and dial a number in the 601 area code and the 644 exchange. Lots of other 


EXC 


e found so 
far. 


bac 


hanges work across the country, I'm sure, but this is the only one that I hav 


Anyway, when it starts ringing, simply hit 2600Hz and you'll hear the kick 
k, (ka- 


chirp, or whatever). Then you are ready to dial whoever you want (conferences, i 
nward, 


rou 


te and rate, overseas, etc.) From the trunk line in operator tones! Since blo 


wing 2600Hz 
doesn't make you a phreaker until the toll equipment resets the line, kickback d 
etection is 


the method AT&T chooses (for now) this information comes as a result of my exper 
iments & 

experience and has been verified by local AT&T employees I have as acquaintances 
. They 

could only say that this is true for my area, but were pretty sure that the same 
idea is 

implemented across the country. 


Now 


that you know how to access a trunk line or as operators say a loop, I will 


tell you the 

many things you can do with it. Here is a list of AT&T services accessible to yo 
u by using a 

blue box. 


A/C 


A/C 


+101 TOLL SWITCHING 


+121 INWARD OPERATOR 


atomic bombs, you wage wars, you murder, cheat, and lie to us and try to make us 


be 
Tt 


Ye 


lieve 
s for our own good, yet we're the criminals. 


s, I am a criminal. My crime is that of curiosity. My crime is that of judgin 


g 
people by what they say and think, not what they look like. My crime is that of 


outsmarting 
you, something that you will never forgive me for. I am a hacker, and this is my 
manifesto. 


You may stop this individual, but you can't stop us all... after all, we're all 
alike. 
+The Mentor++4 


May the members of the phreak community never forget his words -JR 


A/C+131 INFORMATION 


A/C+141 ROUTE & RATE OP. 


A/C+11501 MOBILE OPERATOR 


A/C+11521 MOBILE OPERATOR 


Starting conferences: 


This is one the most useful attributes of blue boxing. Now the confs. are up 24 
hours/day 
and 7 days/week and the billing lines are being billed. Since I believe the abov 
e is true 
(about the billing lines being billed) I would recommend that you never let your 
number show 
up on the conf. If you started it, put it on a loop and then call the loop. Enou 
gh bullshit!!!!! To 

start the conf. Dial one of these three numbers in m-f while you are on the trun 
k. 


213+080+XXXX 
XXXX=1050, 3050 


SPECIAL XXXX=1000,1100,1200,1500,2200,2500. 


These numbers are in LA and are the most watched, I do not advise using this 


NPA. 


312+001+1050 OR 3050 


914+042+1050 OR 1100,1200 ECT.. 


I believe only 914 works at the moment. 


Once connected with one of these you will either hear a re-order, busy, or chirp 
. When you 

hear the chirp enter the billing line in M-F. I use the conf. dial- up. A billin 

g line example: 

kp312+001+1050st you will then hear two tutes and a recording asking you for the 
number 

of conferees including yourself. Enter a number between 20 and 30. If you ever g 

et over 

30 people on a conference all you will hear is jumbled voices. After the it says 
"your 

conference size is xx" then hit the pound (#) sign. Add your favorite loop on an 

d hit 6 to 


transfer control to it. After it says control wi 


ll the ot 
side of t 
r conf. i 
add an in 
otes. Do 
not add n 
You canno 
blow anyo 
y DA 
operators 
least do 
say any n 
han one 


ner 


s to 


he loop, hit the pound sign (#) and fo 


n't 


ternational 


l be transferred hang up and ca 


ow the instructions. A bonus fo 


number dial 1+011+cc+number pretty cool ehhh. A few extra n 


umbers that you will want to hang up, add these through MCI or Sprint. 
ne off with 2600hz unless they are in an old x-bar or older system. Man 
will stay on after you abuse them; you may have to start another or at 


umbers. Never add the tone side of a loop onto a conf. never add more t 


MCI node on your conf. 


Route & r 


Note route & rate and RQS perform the same service. 


nd rate 


ate: 


R&R simply tells you route a 


info which is very valuable, ex. Such as the inward routing for an exchange in a 


n area co 


An inward routing will 


r you. Sh 


can tell you how to get international operators, ect. Here ar 


required 
use: 


Internati 


de. 
e 


to 


onal, 


let you call her and she can do an emergency interrupt fo 


the terms you are 


-Operator route for [country, city]. -gives you inward op. 
-Directory route for [country, city]. -gives you directory ass. 
-City route for [country, city]. -gives you country and city code. 


Operator route for [a/c]+ [exchange] -gives you inward op. Route 


Ex. [a/c]+ or [a/c]+0xx+ when she says plus she means plus 121. 
Numbers route for [state, city] -gives you a/c. 
Place name [a/c]+[exchange] -gives you city/state for that a/c and 


Exchange. 


International calls: 


To call international over cable simply access a trunk and dial kp011xxxst wait 
for sender 

tone, kpxxxcc-numberst xxx - a 3 digit country code, it may not be 3 digits so j 
ust put 1 or 

2 0's in front of it. Cc - is the city code to go by satellite: 


Dial kpl8xst x - numbers 2-8 wait for sender tone then Kpxxxccnumberst 


77. Blue Box by The Jolly Roger 


To quote Karl Marx, blue boxing has always been the most noble form of phreaking 
. AS 
opposed to such things as using an MCI code to make a free fone call, which is m 
erely 
mindless pseudo-phreaking, blue boxing is actual interaction with the Bell Syste 
m toll 

network. It is likewise advisable to be more cautious when blue boxing, but the 

careful 
phreak wi not be caught, regardless of what type of switching system he is und 
er. In this 
part, I wi explain how and why blue boxing works, as well as where. In later p 
arts, I wi 
give more practical information for blue boxing and routing information. To begi 
n with, blue 
boxing is simply communicating with trunks. Trunks must not be confused with sub 
scriber 

ines (or "customer loops") which are standard telefone lines. Trunks are those 

ines that 

connect central offices. Now, when trunks are not in use (i.e., idle or "on-hook 
" state) they 

have 2600Hz applied to them. If they are two-way trunks, there is 2600Hz in both 


directions. When a trunk IS in use (busy or “off-hook" state), the 2600Hz is rem 


oved from 
the side that is off-hook. The 2600Hz is therefore known as a supervisory signal 
, because 
it indicates the status of a trunk; on hook (tone) or off-hook (no tone). Note a 
lso that 
2600Hz denoted SF (single frequency) signaling and is "in-band." This is very im 
portant. 
"TIn-band" means that is within the band of frequencies that may be transmitted o 
ver 
normal telefone lines. Other SF signals, such as 3700Hz are used also. However, 
they 
cannot be carried over the telefone network normally (they are "out-of-band" and 
are 
therefore not able to be taken advantage of as 2600Hz is. Back to trunks. Let's 
take a 
hypothetical phone call. You pick up your fone and dial 1+806-258-1234 (your goo 
d friend in 
Amarillo, Texas). For ease, we'll assume that you are on #5 Crossbar switching a 
nd not in 
the 806 area. Your central office (CO) would recognize that 806 is a foreign NPA 
, so it 
would route the call to the toll center that serves you. [For the sake of accura 
cy here, and 
for the more experienced readers, note that the CO in question is a class 5 with 
LAMA that 
uses out-of-band SF supervisory signaling]. Depending on where you are in the co 
untry, the 
call would leave your toll center (on more trunks) to another toll center, or of 
fice of higher 
"rank". Then it would be routed to central office 806-258 eventually and the cal 
1 would be 
completed. 


Illustration 


A---CO1 TC1 TC2 CO2 B 


A.... you 
COl.. your central office 


TC1.. your toll office. 


TC2.. toll office in Amarillo. 


CO2.. 806-258 central office. 


B.... your friend (806-258-1234) 


In this situation it would be realistic to say that CO2 uses SF in-band (2600Hz) 
signaling, 
while all the others use out-of-band signaling (3700Hz). If you don't understand 
this, don't 
worry. I am pointing this out merely for the sake of accuracy. The point is that 
while you 
are connected to 806-258-1234, all those trunks from YOUR central office (C01) t 
o the 
806-258 central office (C02) do *NOT* have 2600Hz on them, indicating to the Bel 
1 
equipment that a call is in progress and the trunks are in use. Now let's say yo 
u're tired of 
talking to your friend in Amarillo, so you send a 2600Hz down the line. This ton 
e travels 
down the line to your friend's central office (C02) where it is detected. Howeve 
r, that CO 
thinks that the 2600Hz is originating from Bell equipment, indicating to it that 
you've hung 
p, and thus the trunks are once again idle (with 2600Hz present on them). But a 
tually, you 
ave not hung up, you have fooled the equipment at your friend's CO into thinkin 
you have. 
hus, it disconnects him and resets the equipment to prepare for the next call. 
All this 
happens very quickly (300-800ms for step-by-step equipment and 150-400ms for oth 
er 
equipment). When you stop sending 2600Hz (after about a second), the equipment t 
hinks 
that another call is coming towards --> on hook, no tone -->off hook. Now that y 
ou've 
stopped sending 2600Hz, several things happen: 


HO TAG 


A trunk is seized. 


A "wink" is sent to the CALLING end from the CALLED end indicating that the CALL 


ED end 


(trunk) is not ready to receive digits yet. 


A register is found and attached to the CALLED end of the trunk within about two 


seconds 
(max). 


A start-dial signal is 
at the 

CALLED end is ready to 
nt to 

the blue boxer. All he 
rchunk>. 

So, seizure of a trunk 


Send a 2600Hz 
Terminate 2600Hz after 


[beep] [kerchunk] 


Once this happens, you 


command. The next step 
all. For this 


sent to the CALLING end from the CALLED end indicating th 
receive digits. Now, all of this is pretty much transpare 


really hears when these four things happen is a <beep><ke 


would go something like this: 


1-2 secs. 


are connected to a tandem that is ready to obey your ever 


is to send signaling information in order to place your c 


you must simulate the signaling used by operators and automatic toll-dialing equ 


ipment for 


use on trunks. There are mainly two systems, DP and MF. However, DP went out wit 


h the 


+ 


dinosaurs, so I'll only discuss MF signaling. MF (multi-frequency) signaling is 
the signaling 
used by the majority of the inter- and intra-lata network. It is also used in in 
ternational 
dialing known as the CCITT No« system. MF signals consist of 7 frequencies, begi 
nning with 
700Hz and separated by 200Hz. A different set of two of the 7 frequencies repres 
ent the 

digits 0 thru 9, plus an additional 5 special keys. The frequencies and uses are 
as follows: 


Frequencies (Hz) DomesticInternational700+90011700+110022900+110033700+130044900+ 
1300551100+130066700+15007790041500881100+1500991300+150000700+1700ST3pCode 
1900+1700StpCode 11100+1700KPKP11300+1700ST2pKP21500+1700STST 


The timing of all the MF signals is a nominal 60ms, except for KP, which should 

have a 

uration of 100ms. There should also be a 60ms silent period between digits. Thi 

is very 

lexible however, and most Bell equipment will accept outrageous timings. In add 

tion to the 

tandard uses listed above, MF pulsing also has expanded usages known as "expand 

d inband 

ignaling" that include such things as coin collect, coin return, ringback, oper 

tor attached, 

nd operator attached, and operator released. KP2, code 11, and code 12 and the 

T ps 

STart "primes" all have special uses which will be mentioned only briefly here. 

To complete 
a call using a blue box once seizure of a trunk has been accomplished by sending 
2600Hz and 

pausing for the <beep><kerchunk>, one must first send a KP. This readies the reg 
ister for 

the digits that follow. For a standard domestic call, the KP would be followed b 
y either 7 
digits (if the call were in the same NPA as the seized trunk) or 10 digits (if t 


—~NnNOWDAN ODN H-MN A, 


he call were 
not in the same NPA as the seized trunk). [Exactly like dialing normal fone call 
]. Following 


either the KP and 7 or 10 digits, a STart is sent to signify that no more digits 
follow. 
Example of 


a complete call: 


Dial 1-806-258-1234 
Wait for a call-progress indication (such as ring,busy, recording,etc.) 
Send 2600Hz for about 1 second. 


Wait for about ll-progress indication (such as ring, busy, recording,etc.) 


Send KP+305+994+9966+ST 


The call will then connect if everything was done properly. Note that if a call 
to an 806 
number were being placed in the same situation, the are code would be omitted an 
d only KP + 
seven digits + ST would be sent. Code 11 and code 12 are used in international c 
alling to 

request certain types of operators. KP2 is used in international calling to rout 
e a call other 

than by way of the normal route, whether for economic or equipment reasons. STp, 
ST2p, 

and ST3p (prime, two prime, and three prime) are used in TSPS signaling to indic 
ate calling 

type of call (such as coin-direct dialing. 


78. Napalm II by The Jolly Roger 


[See file #021 of the Cookbook for an easy way to make it!!] 


About the best fire bomb is napalm. It has a thick consistency, like jam and is 
best for use 

on vehicles or buildings. Napalms is simply one part gasoline and one part soap. 
The soap is 

ither soap flakes or shredded bar soap. Detergents won't do. The gasoline must 
be heated 


OD 


in order for the soap to melt. The usual way is with a double boiler where the t 
op part has 
at least a two-quart capacity. The water in the bottom part is brought to a boil 
and the 

double boiler is taken from the stove and carried to where there is no flame. Th 
en one part, 

by volume, of gasoline is put in the top part and allowed to heat as much as it 

wi and the 

soap is added and the mess is stirred until it thickens. A better way to heat ga 

soline is to 

fi a bathtub with water as hot as you can get it. It will hold its heat longer 
and permit a 

much larger container than will the double boiler. 


79. Nitroglycerin Recipe by The Jolly Roger 


Like all chemists I must advise you all to take the greatest care and caution wh 
en you are 
doing this. Even if you have made this stuff before. This first article will giv 
e you 
information on making nitroglycerin, the basic ingredient in a lot of explosives 
such as 

straight dynamites, and gelatin dynamites. 


Making nitroglycerin: 


Fill a 75-milliliter beaker to the 13 mL. Level with fuming red nitric acid, of 
98% pure 
concentration. 


Place the beaker in an ice bath and allow to cool below room temp. 


After it has cooled, add to it three times the amount of fuming sulferic acid (9 
9% h2so4). 

In other words, add to the now-cool fuming nitric acid 39 mL. Of fuming sulferic 
acid. 
When mixing any acids, always do it slowly and carefully to avoid splattering. 


When the two are mixed, lower their temp. By adding more ice to the bath, about 
10-15@C. 
Use a mercury-operated thermometer) 


~ 


When the acid solution has cooled to the desired temperature, it is ready for th 
e glycerin. 

The glycerin must be added in small amounts using a medicine dropper. (Read this 
step 

about 10 times!) Glycerin is added slowly and carefully (I mean careful!) Until 
the entire 

surface of the acid it covered with it. 


This is a dangerous point since the nitration will take place as soon as the gly 


cerin is added. 

The nitration will produce heat, so the solution must be kept below 30g@C! If the 
solution 

should go above 30@C, immediately dump the solution into the ice bath! This will 
insure 

that it does not go off in your face! 


For the first ten minutes of nitration, the mixture should be gently stirred. In 
a normal 


reaction the nitroglycerin will form as a layer on top of the acid solution, whi 
le the 
sulferic acid will absorb the excess water. 


After the nitration has taken place, and the nitroglycerin has formed on the top 
of the 
solution, the entire beaker should be transferred slowly and carefully to anothe 
r beaker 

of water. When this is done the nitroglycerin will settle at the bottom so the o 
ther 

acids can be drained away. 


fter removing as much acid as possible without disturbing the nitroglycerin, re 
ove the 
troglycerin with an eyedropper and place it in a bicarbonate of soda (sodium 
icarbonate in case you didn't know) solution. The sodium is an alkali and will 
neutralize 

much of the acid remaining. This process should be repeated as much as necessary 
using 
blue litmus paper to check for the presence of acid. The remaining acid only mak 
es the 
nitroglycerin more unstable than it already is. 


Oo5 3 2 


Hy 


inally! The final step is to remove the nitroglycerin from the bicarbonate. His 
is done with 

and eye- dropper, slowly and carefully. The usual test to see if nitration has b 
een 

successful is to place one drop of the nitroglycerin on metal and ignite it. If 
it is true 
nitroglycerin it will burn with a clear blue flame. 


** Caution ** 


Nitro is very sensitive to decomposition, heating dropping, or jarring, and may 
explode if 
left undisturbed and cool. 


80. Operation: Fuckup by The Jolly Roger 


This is a guide for Anarchists and can be funny for non-believers and 12 and 13 
year old 
runts, and can be a lexicon of deadly knowledge for True Anarchists... Serious d 
amage is 
intended to be dealt here. Do not try this stuff unless you want to do a lot of 
serious 

Anarchy. 


[Simulation] 


Asshole - ‘Listen, you little teenager punk shit, shut the fuck up, or I'll knoc 
k you down!' 


Anarchist - 'O.K. You can't say I didn't warn you. You don't know my rue power.. 
.' (80000 

casually) 

Asshole - 'Well, er, what do you mean? 

Anarchist - '<demoniac grin>' As you can see, the Anarchist knows something that 
this 


asshole doesn't... 


[Operation Fuckup] 


Get a wheel barrel or two. Fill with gasoline. Get 16 rolls of toilet paper, unr 
oll & drench in 

the gasoline. Rip to shreds in gasoline. Get asbestos gloves. Light a flare (to 
be punk), grab 

glob of saturated toilet paper (you can ignite the glob or not). Throw either fl 
aming or 


dripping glob into: 


Any window (picture is the best) 
Front doors 

Rough grain siding 

Best of all, brick walls 


First of all, this bitch is near impossible to get off once dried, and is a terr 
or to peopl 
inside when lit! After this... during the night, get a pickup truck, a few wheel 
-barrels, anda 

dozen friends with shovels. The pickup can be used only for transporting people 
and 

equipment, or doing that, and carting all the dirt. When it gets around 12:00 (a 
fter the 

loser goes beddie - bye), dig a gargantuan hole in his front yard until about 3: 
00. You can 

either assign three or four of your friends to cart the dirt ten miles away in t 
he pickup- 

bed, or bury his front door in 15' of dirt! After that is done, get three or fou 
r buckets of 

tar, and coat his windows. You can make an added twist by igniting the tar when 
you are all 

done and ready to run! That is if the loser has a house. If he lives inside an a 
partment 

building, you must direct the attack more toward his car, and front door. I usua 
lly start out 


O 


when he goes to work...I find out what his cheap car looks like, and memorize it 


for future 
abuse...It 
ka-dots, and 
off-neon co 


inch nails 
T, 


from the 
inside). 


> oO 


leave him an 
axe - that 
one is 


into his front door 
Another great is to fill 
bastard closes 

is door - the only way to get bac 
is, implanted thre 


difficult, but one of the best! Ge 
over his front 


(this looks 


his keyho 


door completely. Nail two by fours on the edges of the siding (a 


ttom) so you 


have a barge - 


h for a 

cement slide. 
cement 
slide 
e more two 


hen it is, 


remove the 'barge' so only a stone mono 


y remaining 


M 


fours to brace your little cement-f3i 


like contraption. Make a hole at the top that will 


ith remains that covers his door. 


is always fun to paint his front door (apt.) hot pink with purple pol 


ors in diagonal stripes. You can also pound a few hundred or so four 


like somebody really doesn't like you 
e with liquid steel so that after th 
k in is to break it down. If you can spare it, 
inches into, and through the door! Now, this next 


t a piece of wood siding that will more than c 


except the bo 


L be large enoug 
ix about six or seven LARGE bags of QUICK drying cement. Use the 
to fill the antechamber created by the 'barge' that is around his door. Us 


ed barge, and let the little gem dry. W 


Use an 


cement to make a base around this so he can't just push it over. When I did this 


, he called 
fir 


ched 


department, and they thought he meant wood, 
with a few dozen or so other tenants, 
ter he parks his car for the night, the fun 


y jamming a very thin, but loack - inside an 


so they brought axes. 


I wat 


and laughed my damn ass off! This is only 
really begins...I start out by ope 


d out! Then proceed to put orange-j 


over the seats, so after he gets through all the other shit that you do, he will 


his door! 

Af 

ning up the car 
b 

uice syrup all 
have the 
stickiest 


seats in the world. You can then get a few Sunday papers, and crack one of the w 


indows 


te 


about four inches. Lightly crumple the papers, and continue to comp 


he inside of 


his car with the newspapers. A copy of the Sunday New York Times wi 


la 


Volkswagen! What is also quite amusing is to put his car on cinder blocks, 


his tires at 


etely fill t 


nicely fil 


slash 


the top, and fill them with cement! Leave the cinder blocks there so that, after 


he knocks 


the car off of them, he will get about 3 mil 


nd do 0 to 60 


L why! 


METAL 


les to the gallon with those tires, a 
in about two minutes! It is even more hilarious when he doesn't know why the hel 


Another is to open his hood, and then run a few wires from the sparkplugs to the 


body. The sure is one HOT car when it is running! Now, I like to pour two pounds 
of sugar 

down his gas tank. If this doesn't blow every gasket in his engine it will do so 

mething called 

‘caramelizing his engine'. This is when the extreme heat turns the sugar to cara 

mel, and you 

literally must completely take the engine out and apart, and clean each and ever 
y individual 

part! Well, if this asshole does not get the message, you had better start to ge 

t serious. If 

this guide was used properly & as it was intended (no, not as kindling for the f 
ire), this 

asshole will either move far away, seek professional psychological help, commit 
suicide, or all 
of the above! 


81. Stealing calls from payphones by The Jolly Roger 


Now to make free local calls, you need a finishing nail. I highly recommend "6D 
E.G. FINISH 

C/H, 2 INCH" nails. These are about 3/32 of an inch in diameter and 2 inches lon 
g (of 


course). You also need a large size paper clip. By large I mean they are about 2 
in long 

(FOLDED). Then you unfold the paper clip. Unfold it by taking each piece and mov 
ing it out 

90g. When it is done it should look somewhat like this: 


eo 


Now, on to the neat stuff. 
piece, 
is insert the nail into the center hole of the mouthpiece (where you talk) and p 
ush it in 
with pressure or just hammer it in by hitting the nail on something. Just DON'T 
KILL THE 
MOUTHPIECE! You could damage it if you insert the nail too far or at some weird 


What you do, instead of unscrewing the glued-on mouth 


If this happens then the other party won't be able to hear what you say. You now 


hole in the mouthpiece in which you can easily insert the paper clip. So, take o 
ut the nail and 

put in the paper clip. Then take the other end of the paper clip and shove it un 
d 

t 

T 


ubber cord protector at the bottom of the handset (you know, the blue guy...). 
his should 
end up looking remotely like...like this: 


P EEE \ Mouthpiece 

Paper clip t= iy 
/---:---\ 

do e ee, > 

=============== N LLL) ) ) 


To earpiece -> 


N A 


Cord Blue guy 


(The paper clip is shoved under the blue guy to make a good connection between t 
he inside 

of the mouthpiece and the metal cord.) Now, dial the number of a local number yo 
u wish to 
call, sayyyy, MCI. If everything goes okay, it should ring and not answer with t 
he "The Call 
You Have Made Requires a 20 Cent Deposit" recording. After the other end answers 
the 
phone, remove the paper clip. It's all that simple, see? There are a couple prob 
lems, 
however. One is, as I mentioned earlier, the mouthpiece not working after you pu 
nch it. 

If this happens to you, simply move on to the next payphone. The one you are now 
on is 

lost. Another problem is that the touch tones won't work when the paper clip is 
in the 

mouthpiece. There are two ways around this.. 


Dial the first 6 numbers. This should be done without the paper clip making the 
connection, 
i.e., one side should not be connected. Then connect the paper clip, hold down t 
he last 

digit, and slowly pull the paper clip out at the mouthpiece's end. 


Don't use the paper clip at all. Keep the nail in after you punch it. Dial the f 
irst 6 

digits. Before dialing the last digit, touch the nail head to the plate on the m 
ain body of 

the phone, the money safe thingy..then press the last number. The reason that th 
is 
method is sometimes called clear boxing is because there is another type of phon 
e 
which lets you actually make the call and listen to them say "Hello, hello?" but 
it 

cuts off the mouthpiece so they can't hear you. The Clear Box is used on that to 


amplify your voice signals and send it through the earpiece. If you see how this 

nese similar to the method I have just described up there, kindly explain it 

t 1] 
E oe GET IT! Anyways, this DOES work on almost all single slot, Dial To 

First payphones (Pacific Bell for sure). I do it all the time. This is the least 
I 


n 


Hy 


mr 


TRESS *LEAST*, risky form of Phreaking. 


82. Pool Fun by The Jolly Roger 


First of all, you need know nothing about pools. The only thing you need know is 
what a pool 

filter looks like. If you don't know that. Second, dress casual. Preferably, in 
black. Visit 

your "friends" house, the one whose pool looks like fun!! Then you reverse the p 
olarity of 

his/her pool, by switching the wires around. They are located in the back of the 
pump. This 


will have quite an effect when the pump goes on. In other words. Booooooooocoomm 
m! 

That's right, when you mix + wires with - plugs, and vice- versa, the 4th of Jul 
y happens 
again. Not into total destruction??? When the pump is off, switch the pump to "b 
ackwash". 
Turn the pump on and get the phuck out! When you look the next day, phunny. The 
pool is 
dry. If you want permanent damage, yet no great display like my first one mentio 
ned, shut 

the valves of the pool off. 
n and one 

that goes to the filter in the pool. That should be enough to have one dead pump 
. The pump 

must take in water, so when there isn't any... Practical jokes: these next ones 

deal with 

true friends and 


(There are usually 2) One that goes to the main drai 


there is *no* permanent damage done. If you have a pool, you must check the pool 
with 
chemicals. There is one labeled orthotolidine. The other is labeled alkaline (pH 


). You want 

orthotolidine. (It checks the chlorine). Go to your local pool store and tell th 
em you're going 
into the pool business, and to sell you orthotolidine (a CL detector) Buy this i 
n great 
quantities if possible. The solution is clear. You fill 2 baggies with this chem 
ical. And sew 
the bags to the inside of your suit. Next, go swimming with your friend! Then op 
en the bags 
and look like you're enjoying a piss. And anyone there will turn a deep red! The 
y will be 
embarrassed so much, Especially if they have guests there! Explain what it is, t 
hen add 
vinegar to the pool. Only a little. The "piss" disappears. 


83. Free Postage by The Jolly Roger 


The increasing cost of postage to mail letters and packages is bringing down our 
standard of 

living. To remedy this deplorable situation, some counter control measures can b 
e applied. 
For example, if the stamps on a letter are coated with Elmer's Glue by the sende 
r, the 
cancellation mark will not destroy the stamp: the Elmer's drives to form an almo 
st invisible 

coating that protects the stamps from the cancellation ink. Later, the receiver 
of the 


letter can remove the cancellation mark with water and reuse the stamps. Further 
more, 


ecological saving will also result from recycling the stamps. Help save a tree. 
The glue is 
most efficiently applied with a brush with stiff, short bristles. Just dip the b 


rush directly 
into the glue and spread it on evenly, covering the entire surface of the stamp. 
It will dry in 
about 15 minutes. For mailing packages, just follow the same procedure as outlin 
ed above; 
however, the package should be weighed and checked to make sure that it has the 
correct 
amount of postage on it before it is taken to the Post Office. Removing the canc 
ellation and 
the glue from the stamps can be easily accomplished by soaking the stamps in war 
m water 
until they float free from the paper. The stamps can then be put onto a paper to 
wel to dry. 
Processing stamps in large batches saves time too. Also, it may be helpful to wr 
ite the word 
'Elmer' at the top of the letter (not on the envelope) to cue the receiving part 
y in that the 
stamps have been protected with the glue. We all know that mailing packages can 
be 
expensive. And we also know that the handicapped are sometimes discriminated aga 
inst in 
jobs. The Government, being the generous people they are, have given the blind f 
ree postal 
service. Simply address you envelope as usual, and make one modification. In the 
corner 
where the stamp would go, write in (or stamp) the words 'FREE MATTER FOR THE BLI 
ND". 
Then drop you package or letter in one of the blue federal mailboxes. DO NOT TAK 
E THE 
LETTER TO THE POST OFFICE, OR LEAVE IT IN YOUR MAILBOX. Sounds very nice of 
the government to do this, right? Well, they aren't that nice. The parcel is sen 


t library 

rate, that is below third class. It may take four to five days to send a letter 
to just the 

next town. This too is quite simple, but less effective. Put the address that yo 


u are sending 

the letter to as the return address. If you were sending a $20 donation to the p 
irate's 

Chest, you would put our address (PO box 644, Lincoln MA 01773) as the return ad 
dress. 

Then you would have to be careless and forget to put the stamp on the envelope. 
A nice 

touch is to put a bullshit address in the center of the envelope. Again, you MUS 
T drop the 

letter in a FEDERAL mailbox. If the post office doesn't send the letter to the r 
eturn 
address for having no stamp, they will send it back for the reason of "No such a 
ddress". 


Example: 


Pirates Chest Dept. 40DD 
P.O. Box 644865 


Lincol, Ma. 41773 


Tom Bullshit 
20 Fake Road 


What Ever, XX 99851 


One last thing you might try doing is soaking a canceled stamp off of an envelop 
e, and gluing 

it onto one you are sending. Then burn the stamp, leaving a little bit to show t 
hat there was 

one there. 


84. Unstable Explosives by The Jolly Roger 


Mix solid Nitric Iodine with household ammonia. Wait overnight and then pour off 
the liquid. 

You will be left with a muddy substance. Let this dry till it hardens. Now throw 
it at 
something!!!! 


85. Weird Drugs by The Jolly Roger 


Bananas: 

Obtain 15 pounds of ripe yellow bananas. 

Peel all and eat the fruit. Save the peelings. 

Scrape all the insides of the peels with a sharp knife. 
Put all the scraped material in a large pot and add water. 


Boil 3 or 4 hours until it has attained a solid paste consistency. 


Spread paste onto cookie sheets and dry in oven for about 20 minutes. This will 
result in 
fine black powder. Usually one will feel the effects after smoking three to four 


cigarettes. 


Cough syrup: 
Mix Robitussion AC with an equal amount of ginger ale and drink. The effect are 
sedation 


and euphoria. Never underestimate the effects of any drug! You can OD on cough s 
yrup! 


Toads: 


Collect five to ten toads, frogs will not work. The best kind are tree toads. 


Ki them as painlessly as possible, and skin immediately. 


Allow the skins to dry in a refrigerator four to five days, or until the skins a 
re brittle. 


Now crush the skins into powder and smoke. Due to its bad taste you can mix it w 
ith a more 
fragrant smoking medium. 


Nutmeg: 


Take several whole nutmegs and grind them up in an old grinder. 


After the nutmegs are ground. Place in a mortar and pulverize with a pestle. 


The usual dosage is about 10 or 15 grams. A larger dose may produce excessive th 
LES, 
anxiety, and rapid heart beat, but hallucinations are rare. 


Peanuts: 
Take 1 pound of raw peanuts (not roasted.) 
Shell them, saving the skins and discarding the shells. 


Eat the nuts. 


Grind up the skins and smoke them. 


86. The Art of Carding by The Jolly Roger 


Obtaining a credit card number: There are many ways to obtain the information ne 
eded to 

card something. The most important things needed are the card number and the exp 
iration 

date. Having the card-holders name doesn't hurt, but it is not essential. The ab 
solute best 


way to obtain all the information needed is by trashing. The way this is done is 
simple. You 

walk around your area or any other area and find a store, mall, supermarket, etc 
., that 

throws their garbage outside on the sidewalk or dumpster. Rip the bag open and s 
ee if you 
can find any carbons at all. If you find little shreds of credit card carbons, t 

hen it is most 

ikely not worth your time to tape together. Find a store that does not rip thei 

r carbons at 

all or only in half. Another way is to bullshit the number out of someone. That 

is call them 

up and say "Hello, this is Visa security and we have a report that your card was 

stolen." 

They will deny it and you will try to get it out of them from that point on. You 
could say, "It 

wasn't stolen? Well what is the expiration date and maybe we can fix the problem 


vese "OK 
and what is the number on your card?...... Thank you very much and have a nice da 
y." Or 


think of something to that degree. Another way to get card numbers is through sy 
stems 

such as TRW and CBI, this is the hard way, and probably not worth the trouble, u 
nless you 

are an expert on the system. Using credit card numbers posted on BBS's is risky. 
The only 

advantage is that there is a good chance that other people will use it, thus dec 
reasing the 

chances of being the sole-offender. The last method of getting numbers is very g 
ood also. 
In most video rental stores, they take down your credit card number when you joi 
n to back- 
up your rentals. So if you could manage to steal the list or make a copy of it, 
then you are 

set for a LONG time. Choosing a victim: Once you have the card number, it is tim 
e to make 

the order. The type of places that are easiest to victimize are small businesses 
that do 

mail order or even local stores that deliver. If you have an ad for a place with 
something you 

want and the order number is NOT a 1-800 number then chances are better that you 
will 

succeed. 


Ordering 


When you call the place up to make the order, you must have several things readi 

ly at hand. 

These are the things you will need: A name, telephone number, business phone, ca 

rd number 

(4 digit bank code if the card is MasterCard), expiration date, and a complete s 

hipping and 

billing address. I will talk about all of these in detail. A personal tip: When 

I call to make an 

order, it usually goes much smoother if the person you are talking to is a woman 
In many 

cases they are more gullible than men. The name: You could use the name on the c 


ard or the 

name of the person who you are going to send the merchandise to. Or you could us 
e the 

name on the card and have it shipped to the person who lives at the drop (Say it 
is a gift or 

something). The name is really not that important because when the company verif 

ies the 

card, the persons name is never mentioned, EXCEPT when you have a Preferred Visa 

card. 

Then the name is mentioned. You can tell if you have a Preferred Visa card by th 
e PV to the 

right of the expiration date on the carbon. No phone all day long waiting for th 
e company to 
call (Which they will), then the phone number to give them as your home-phone co 

uld be one 
O 

y 

n 


f the following: A number that is ALWAYS busy, a number that ALWAYS rings, a pa 
phone 

umber, low end of a loop (and you will wait on the other end), or a popular BBS 
NEVER give 
hem your home phone because they wi find out as soon as the investigation sta 
ts who the 
hone belongs to. The best thing would be to have a payphone call forward your h 
use (via 

osm The business number.) When asked for, repeat the number you used for your h 
e 
hone. Card number: The cards you will use will be Visa, Mastercard, and America 
Express. 
he best is by far Visa. It is the most straight-forward. Mastercard is pretty c 
ol except 

or the bank code. When they ask for the bank code, they sometimes also ask for 
he bank 

hat issued it. When they ask that just say the biggest bank you know of in your 
area. Try 


8 


tTrtMmhHoOoHD WTO QOS K cs 


to avoid American Express. They tend to lead full scale investigations. Unfortun 
ately, 
American Express is the most popular card out. When telling the person who is ta 
king your 
call the card number, say it slow, clear, and with confidence. e.g. CC# is 5217- 
1234-5678- 
9012. Pause after each set of four so you don't have to repeat it. Expiration da 
te: The date 
must be at LEAST in that month. It is best to with more than three months to go. 
The 
address: More commonly referred to as the 'drop'. Well the drop can range from a 
n 
abandoned building to your next door neighbors apartment. If you plan to send it 
to an 
apartment building then be sure NOT to include an apartment number. This will co 
nfuse 
UPS or postage men a little and they will leave the package in the lobby. Here i 
s a list of 
various drops: The house next door whose family is on vacation, the apartment th 
at was just 
moved out of, the old church that will be knocked down in six months, your frien 
ds house 
who has absolutely nothing to do with the type of merchandise you will buy and w 
ho will also 
not crack under heat from feds, etc.. There are also services that hold merchand 
ise for 
you, but personally I would not trust them. And forget about P.O. Boxes because 
you need 
ID to get one and most places don't ship to them anyway. Other aspects of cardin 
g: 
Verifying cards, seeing if they were reported stolen. Verifying cards: Stores ne 
ed to verify 
credit cards when someone purchases something with one. They call up a service t 
hat 
checks to see if the customer has the money in the bank. The merchant identifies 
himself 
with a merchant number. The service then holds the money that the merchant verif 
ied on 
reserve. When the merchant sends in the credit card form, the service sends the 
merchant 
the money. The service holds the money for three days and if no form appears the 
nit is 
put back into the bank. The point is that if you want to verify something then y 
ou should 
verify it for a little amount and odds are that there will be more in the bank. 
The good thing 
about verification is that if the card doesn't exist or if it is stolen then the 
service will tell 
you. To verify MasterCard and Visa try this number. It is voice: 1-800-327-1111 
merchant 
code is 596719. Stolen cards: Mastercard and Visa come out with a small catalog 
every 


week where they publish EVERY stolen or fraudulently used card. I get this every 
week by 
trashing the same place on the same day. If you ever find it trashing then try t 
o get it 
every week. Identifying cards: Visa card numbers begin with a 4 and have either 
13 or 16 


digits. MasterCard card numbers begin with a 5 and have 16 digits. American Expr 
ess 
begins with a 3 and has 15 digits. They all have the formats of the following: 


3XXX-XXXXXX-XXXXxX American Express 
4xxXxX-XXX-XXX-XxXxX Visa 
4XxXX-XXXX-XXXX-XXXX ViSa 


5XXX-XXXX-XXXX-XXXX MasterCard 


Gold cards: A gold card simply means that credit is good for $5000. Without a go 
ld card, 
credit would be normally $2000. To recognize a gold card on a carbon there are s 
everal 
techniques: 


American Express-—none. 


Visa-PV instead of CV. 


Note-When verifying a PV Visa, you have to have the real name of the cardholder. 


Mastercard-An asterisk can signify a gold card, but this changes depending when 
the card 

was issued. I am going to type out a dialog between a carder and the phone opera 
tor to help 

you get the idea. 


Operator: “Over-priced Computer Goods, may I help you?" 
Carder: "Hi, I would like to place an order please." 
Operator: "Sure, what would you like to order?" 

Carder: "400 generic disks and a double density drive." 
Operator: "Ok, is there anything else?" 

Carder: "No thank you, that's all for today." 

Operator: "Ok, how would you like to pay for this? MasterCard or Visa?" 
Carder: "Visa." 

Operator: "And your name is?" 

Carder: "Lenny Lipshitz." (Name on card) 

Operator: "And your Visa card number is?" 

Carder: "4240-419-001-340" (Invalid card) 

Operator: “Expiration date?" 

Carder: "06-92." 

Operator: "And where would you like the package shipped to?" 


Carder: "6732 Goatsgate Port. Paris, Texas, 010166." 


Operator: "And what is your home telephone number?" 


Carder: "212-724-9970" (This number is actually always busy) 


Operator: "I will also need your business phone number in case we have to reach 
you." 


Carder: "You can reach me at the same number. 212-724-9970" 
Operator: "O.K. Thank you very much and have nice day." 
Carder: "Excuse me, when will the package arrive?" 
Operator: "In six to seven days UPS." 


Carder: "Thanks a lot, and have a pleasant day." 


Now you wait 6-7 days when the package will arrive to the address which is reall 
y a house up 
for sale. There will be a note on the door saying, "Hello UPS, please leave all 
packages for 

Lenny Lipshitz in the lobby or porch. Thanks a lot, Lenny Lipshitz" (Make the si 
gnature 

half-way convincing) 


87. Recognizing credit cards by The Jolly Roger 


[Sample: American Express] 
XXXX XXXXXX XXXXX 
MM/Y1 THRU MM/Y2 Y1 


John Doe AX 


Explanation: 


The first date is the date the person got the card, the second date is the expir 


ation date, 
after the expiration date is the same digits in the first year. The American Exp 


ress Gold 


has many more numbers (I think 6 8 then 8). If you do find a Gold card keep it f 
or it has a 
$5000.00 backup even when the guy has no money! 


[Sample: Master Card] 
5XXX XXXX XXXX XXXX 
XXXX AAA DD-MM-YY MM/YY 


John Doe. 


Explanation: 


The format varies, I have never seen a card that did not start with a 5XXX there 
is 

another 4 digits on the next line that is sometimes asked for when ordering stuf 
f, (and 

rarely a 3 digit letter combo (e. ANB). The first date is the date the person go 

t the card 

and the second date is the expiration date. Master Card is almost always accepte 
d at 

stores. 


[Sample: VISA] 
XXXX XXX (X) XXX(X) XXX (X) 
MM/YY MM/YY*VISA 


John Doe 


Explanation: 


Visa is the most straight forward of the cards, for it has the name right on the 
card itself, 

again the first date is the date he got the card and the second is the expiratio 

n date. 
(Sometimes the first date is left out). The numbers can either be 4 3 3 3 or 4 4 
4 4, Visa is 


also almost always accepted at stores, therefore, the best of cards to use. 


88. How To Create A New Identity by The Walking Glitch 


You might be saying, "Hey Glitch, what do I need a new identity for?" The answer 
is simple. 
You might want to go buy liquor somewhere, right? You might want to go give the 


cops the 

false name when you get busted so you keep your good name, eh? You might even wa 
nt to 
use the new identity for getting a P.O. Box for carding. Sure! You might even wa 
nt the stuff 

for renting yourself a VCR at some dickless loser of a convenience store. Here w 
e go: 

Getting a new ID isn't always easy, no one said it would be. By following these 
steps, any 

bozo can become a new bozo in a couple of weeks. 


STEP 1 


The first step is to find out who exactly you'll become. The most secure way is 
to use 

someone's ID who doesn't use it themselves. The people who fit that bill the bes 
t are dead. 

As an added bonus they don't go complaining one bit. Go to the library and look 
through old 
death notices. You have to find someone who was born about the same time as you 

were, or 

better yet, a year or two older so you can buy booze, etc. You should go back as 
far as you 

can for the death because most states now cross index deaths to births so people 
can't do 

this in the future. The cutoff date in Wisconsin is 1979, folks in this grand st 
ate gotta look 
in 1978 or earlier. Anything earlier there is cool. Now, this is the hardest par 
t if you're 


younger. Brats that young happen to be quite resilient, taking falls out of thre 
e story 
windows and eating rat poison like its Easter candy, and not a scratch or dent. 
There ain't 
many that die, so ya gotta look your ass off. Go down to the library and look up 
all the death 
notices you can, if it's on microfilm so much the better. You might have to go t 
hrough 
months of death notices though, but the results are well worth it. You gotta get 
someone 
who died locally in most instances: the death certificate is filed only in the c 
ounty of death. 
Now you go down to the county courthouse in the county where he died and get the 
death 
certificate, this will cost you around $3-$5 depending on the state you're in. L 
ook at this 
hunk of paper, it could be your way to vanish in a cloud of smoke when the right 
time comes, 
like right after that big scam. If You're lucky, the slobs parents signed him up 
with social 
security when he was a snot nosed brat. That'll be another piece of ID you can g 
et. If not, 
that's Ok too. It'll be listed on the death certificate if he has one. If you're 
lucky, the 
stiff was born locally and you can get his birth certificate right away. 


STEP 2 


Now check the place of birth on the death certificate, if it's in the same place 
you standing 

now you're all set. If not, you can mail away for one from that county but its a 
minor pain 
and it might take a while to get, the librarian at the desk has listings of wher 
e to write for 

this stuff and exactly how much it costs. Get the Birth certificate, its worth t 
he extra 

money to get it certified because that's the only way some people will accept it 
for ID. 

When you're getting this stuff the little forms ask for the reason you want it, 
instead of 

writing in "Fuck you", try putting in the word "Genealogy". They get this all th 
e time. If the 

Death certificate looks good for you, wait a day or so before getting the certif 
ied birth 

certificate in case they recognize someone wanting it for a dead guy. 


STEP 3 


Now your cooking! You got your start and the next part's easy. Crank out your ol 
d Dot 
matrix printer and run off some mailing labels addressed to you at some phony ad 


dress. 

Take the time to check your phony address that there is such a place. Hotels tha 
t rent by 

the month or large apartment buildings are good, be sure to get the right zip co 
de for the 

area. These are things that the cops might notice that will trip you up. Grab so 
me old junk 

mail and paste your new labels on them. Now take them along with the birth certi 
ficate 
down to the library. 


Get a new library card. If they ask you if you had one before say that you reall 
y aren't sure 

because your family moved around a lot when you were a kid. Most libraries wil 
allow you to 

use letters as a form of ID when you get your card. If they want more give them 
a sob 
story about how you were mugged and got your wallet stolen with all your identif 
ication. 
Your card should be waiting for you in about two weeks. Most libraries ask for t 
wo forms of 

ID, one can be your trusty Birth Certificate, and they do allow letters addresse 
d to you as a 

second 


form. 


STEP 4 


Now you got a start, it isn't perfect yet, so let's continue. You should have tw 
o forms of ID 

now. Throw away the old letters, or better yet stuff them inside the wallet you 
intend to 

use with this stuff. Go to the county courthouse and show them what nice ID you 
got and 

get a state ID card. Now you got a picture ID. This will take about two weeks an 
d cost 

about $5, its well worth it. 


STEP 5 

If the death certificate had a social security number on it you can go out and b 
uy one of 

those metal SS# cards that they sell. If it didn't, then you got all kinds of pr 
etty ID that 

shows exactly who you are. If you don't yet have an SS#, Go down and apply for o 
ne, these 

are free but they could take five or six weeks to get, Bureaucrats you know... Y 
ou can invent 

a SS# too if you like, but the motto of 'THE WALKING GLITCH' has always been "Wh 
y not 

excellence?". 

STEP 6 


If you want to go whole hog you can now get a bank account in your new name. If 

you plan to 

do a lot of traveling then you can put a lot of money in the account and then sa 

y you lost the 

account book. After you get the new book you take out all the cash. They'll hit 

you with a 

slight charge and maybe tie-up your money some, but if you're ever broke in some 
small 

town that bank book will keep you from being thrown in jail as a vagrant. 


ALL DONE? 


So kiddies, you got ID for buying booze, but what else? In some towns (the large 
r the more 
likely) the cops if they catch you for something petty like shoplifting stuff un 
der a certain 
dollar amount, will just give you a ticket, same thing for pissing in the street 
. That's it! No 
fingerprints or nothing, just pay the fine (almost always over $100) or appear i 


n court. Of 

course they run a radio check on your ID, you'll be clean and your alter-ego get 
s a blot on 
his record. Your free and clear. That's worth the price of the trouble you've go 
ne through 
right there. If your smart, you'll toss that ID away if this happens, or better 
yet, tear off 

your picture and give the ID to someone you don't like, maybe they'll get busted 
with it. If 
you're a working stiff, here's a way to stretch your dollar. Go to work for as 1 
ong as it takes 

to get unemployment and then get yourself fired. Go to work under the other name 
while 
your getting the unemployment. With a couple of sets of ID, you can live like a 
king. These 
concepts for survival in the new age come to you compliments of THE WALKING GLIT 
CH. 
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Raggers and Braggers 


This section is to make you aware of well-known raggers and braggers. Since this 
is the 
first time this section is being printed, we will tell you what classifies peopl 
e as raggers and 

braggers. In the future issues the top raggers and braggers will be listed in th 
is 

newsletter to let the SysOps know who not to let on their board, or to atleast k 

eep an eye 


on. A ragger is someone who will put someone else down for something. The person 
might 
post a message asking a novice question about hacking and phreaking, or may say 
something that is completely wrong, and a ragger will put the other person down 
for he 
said, posted, etc. The ones that usually classify in this category are the ones 
that think 
they know it all and consider themselves right no matter what anyone says. Most 
of the 

users that use codes and consider themselves a master phreaker usually become ra 
ggers. 


A bragger is someone who either does or thinks he does know everything, and puts 
it upon 

himself to tell the whole world that he knows it all. This person is also one wh 
o thinks he 
is better than everyone else and he believes he is Elite, and no one else is. Pe 
ople who 

tend to do this are those who have, for some reason, become well-known in the un 
derworld, 

and as a result become a bragger. Those usually not too well-known will not tend 
to brag 

as much as those who think everyone would love to be their friend and be like th 
em. 


As a well-known ragger and bragger, The Toad, learned that it does not help to b 
e one or 
both of those. He has since changed and is now easily accepted by most. Most peo 
ple 

disliked him because others they knew had said something bad about him. This is 

called 

peer pressure and is a bad influence to those who are new to the underworld. I w 
ould 

suggest in the future, to not judge someone by what others say, but rather by ho 
w they act 

around/to you. The current most popular Atarian that classifies as a ragger and 

a bragger 

is Ace of Aces, and is well-hated by many users and SysOps, since he tends to pu 
t down 

anything anyone says and considers himself the best at writing hacking programs. 
He is 
commonly referred to as Ass of Asses and Ass of Assholes. Even holding an open m 
ind about 

this guy, you would soon come to find that what others said coincides with what 

you see 

from him. 


A New 950 has arrived! 


LDDS, who as mentioned above bought out TMC, is installing a new 950 port to mos 
t major 

cities. By the time you read this, it should be in almost every area that suppor 
ts 950 


ports. The number is 950-1450. This port will dial 976 numbers, but not 700, 800 
, or 900 
numbers. The dialing method for LDDS is: 7 digit code, then even if the code is 


bad it 

will give you a dial tone. Then dial the area code plus the number. If you have 
a bad code 

it will simply say your call cannot be completed as it was dialed. There is a de 
fault code 


used on the system that currently works. The code is simply, 1234567. I have see 
n codes 
from 5 different companies and they all are in the format of 00xxxxx. I do not k 
now 
what type of software they use, but I will know by the next issue exactly what t 
hey 
place on the bills. This could be the answer to a lot of people's problems with 
fear of 
Sprint and ITT, especially AllNets. Just remember, Tracker is the one who found 
this, 
and a information about it. If someone is seen saying they found this, then th 
ey wi be 
listed in the next issue which will contain an article on leeches. 


Mailbox Systems 


Mailbox systems are the link between information and the underworld. If you have 
ever 
called one, then you will know the advantages of having one, especially the ones 
that are 
open to whole underworld, rather than just a select few. There are two types of 

mailbox 

systems that are widely used. The first type we will talk about is the multiple 

mailbox 


systems, or commonly referred to as message systems. These systems have several 
mailboxes set up on one number. Usually, you can access other mailboxes from tha 
t 


number by pressing '*' or '#'. Sometimes you just enter the mailbox number and y 
ou are 

connected. These are the safest systems to use to protect information from US Sp 
T 

O 


int and 

ther long distance companies. Since US Sprint and other companies call the dest 
ination 
numbers, it is safer to have 800 mailbox systems, and most of the time, the mult 
iple 
mailbox systems are on 800 numbers. The passcode on these systems can vary in le 
ngth 
and can be accessed by several different methods, so it is impossible to explain 
exactly 

how to hack these systems. 


The other type is the single mailbox system. These are usually set up in a reser 
ved prefix 
in an area code. (Ex: 713-684-6xxx) These systems are usually controlled by the 
same 

type of hardware/software. To access the area where you enter the passcode, just 
hit 
'0' for a second or so. The passcodes are four (4) digits long. The only way to 
hack these 

is manually. The best thing you could do is to find one that does not have a rec 
ording from 


a person, but just the digitized voice. If you hack one that someone already own 
s, they 
will report it and it will not last as long. 


Here is a list mailboxes or prefixes to help you get started 


SingleMultipleNameDigits213-281-8xxx212-714-2770 3213-285-8xxx216-586-5000 4213- 
515-2xxx415-338-7000Aspen Message System3214-733-5xxx714-474-2033Western 
Digital 214-855-6xxx800-222-0651Vincent and Elkins4214-978-2xxx800-233-8488 3215 


949-2xxx800-447-8477Fairylink7312-450-8xxx800-521-5344 3313-768-1xxx800-524- 
2133RCA4405-557-8xxx800-527-0027TTE TeleMessager6602-230-4xxx800-632- 
7777Asynk6619-492-8xxx800-645-7778So0ftCell Computers4713-684-6xxx800-648- 
9675Zoykon4 800-847-0003Communications World3 
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Introduction 


It's been a month now, and A LOT has happened. So much, in fact, that the inform 
ation will 
be split into several issues. This should be no shock since I mentioned in the f 


irst issue that 

we may put several issues out sometimes. I want to congratulate the readers for 
finally 

contributing to the newsletter. This first two issues were all on information th 
at I, myself, 

obtained. Several people gave me information for these issues, and their handle 
and 

information is included in the articles. 


ITT has 9 digits! 


For those of you who did not know this, ITT has nine digit codes. They are said 
to give 
better connections to some extent. This info was originally given to us by Party 
Beast. 


Phreaky Phones Go Down! 


he famed Phreaky Phones are down again. Modem Man, the original person that sta 
ted 
hem, has said that they will be down until further notice. In the meantime, oth 


ndependent boxes are being started. A listing can be made of current ones on re 
uest. 


QrEOtHH 


Magnus Adept Gets Busted 


Fellow Atarian and well-known phreak Magnus Adept got caught by MCI. Details of 
the how, 

when, and where are not known at this time. He got caught with 150 codes and may 
have to 

pay up to 50 dollars for each code. 


Sprint Codes Are Dying Fast! 


Sprint codes are hard to get and when they are obtained, they tend to die rather 
quickly. 

Phreakers have been saying that the 950-0777 port is dead, but on the contrary, 
it is still 

available in states that are not highly abused by phreaks. Here again, rumors ar 
e being 

spread. 


The Best BBS of the Month 


Starting from now on, we will have a BBS of the month. We will choose a BBS, reg 
ardless of 

computer type, and look at the user participation in phreak related matters, as 
well as 
quality discussions on the various illegal topics. A BBS can remain the BBS of t 
he month as 

long as they reside above the rest of the BBS systems. Even though we will somet 
imes 

bring out more than one issue in a month, the board will remain BBS of the month 
until the 

first issue in the next month comes out. 


This month's BBS of the month is FBI PirateNet. We chose this board because of t 
he large 
numbers of posts in the bases, and not only information, but discussions as well 
, with a 
minimum number of posts from raggers and braggers. The number for it is 516-661- 
7360. 
The Sysop of FBI PirateNet is The Phantom, not to be confused with an earlier NA 
RC. 


US Sprint Expected to Trim Staff, Consolidate Divisions 


New York -- US Sprint Communications Corp., the troubled long distance carrier, 
is 

expected to announce soon that it will cut its work force by several hundred peo 
ple and 


reduce its seven regional divisions to 3 operating groups, sources familiar with 
the company 
said. 


The company's Pacific division is based in Burlingame, CA. The layoffs and reorg 
anization 

are part of a plan by US Sprint's new president, Robert H. Snedaker, to reduce h 
eavy 
operating losses, which analysts expect to reach more than $800 million this yea 
Y 


Snedaker replaced Charles M. Slibo, who was forced to resign in July because los 
ses were 

running much higher than the parent companies had expected. Problems with the co 
mpany's 

computerized billing system also contributed to Skibo's ouster. US Sprint is own 
ed and 

operated by the GTE Corp. and United TeleCom. 


According to sources close to Snedaker, who was vice chairman and chief operatin 
g officer 
of United TeleCom, he is planning to consolidate the company's 7 divisions, whic 
h operate in 

the same geographical regions as the seven regional Bell operating companies, in 
to 3 

divisions. 


The rationale for the move, according to industry analysts, is that the company 
will need a 
much smaller work force once it begins handling all it's phone traffic on it's n 


ew fiber optic 
network, which can carry a greater number of telephone calls at less cost. Compa 


ny 
officials have said that they expect to have most of the traffic on the network 
by early 


next year. One source said that there would be more than one round of layoffs in 
the 

coming months and that the company ultimately plans to reduce its 14,000 member 
work 

force by 15 percent. 


Several top managers are expected to resign as soon as US Sprint centralizes its 
marketing 

and support operations as its headquarters in Kansas City, MO., according toar 
eport in the 

latest issue of Business Week magazine. 


A spokesman for US Sprint said on Friday that the company would not comment on t 
he 

rumors. The company is the nation's third largest long distance company, after t 
he 

American Telephone and Telegraph Co. (AT&T) and MCI Communications Co. 


Last year, Washington based MCI undertook a similar reorganization in which it p 
osted a 
$502« million loss to write down old inventory and restructure operations. 


Analysts said that is US Sprint is to turn a profit, the company must increase i 
ts market 

share. "To do this, US Sprint must gain more large business customers, which acc 
ount for 

about 80 percent of industry revenues," said Robert B. Morris III, Securities in 
San 

Francisco. 


£ 


Morris said that by using a slick marketing campaign to differentiate its all-f3i 

ber telephone 

network from those of competitors, US Sprint more than doubled its customer base 
last 

year. But "most of these customers were residential and small business users tha 

t added 

little to Sprint's bottom line," he added. "If the company expects to be profita 

ble, it will 

have to concentrate on providing the best service to volume users." 


Secret Service Cracks Down on Teen Hackers 


Mount Lebanon, PA The US Secret Service and local police departments have put 
a scare 
into the hacker community with a nationwide crackdown on computer crime that has 


resulted in the arrests of teenage hackers in at least three cities. 


"People who monitor the bulletin boards say there are a lot of nervous hackers o 
ut there, 

wondering who will be arrested next," says Ronald E. Freedman, vice-president of 
Advanced 

Information Management, a Woodbridge, VA base computer security firm. 


E 


Nine teenagers from Mount Lebanon Junior-Senior High School near Pittsburg, PA, 
were 
arrested recently and charged with computer fraud. The juveniles allegedly used 
home 
computers to gain illegal access to a credit card authorization center. They obt 
ained valid 

credit card numbers and used them to purchase thousands of dollars worth of mail 

order 
merchandise, the police said. 


Freedman says it appears the hackers used some relatively sophisticated techniqu 
es in the 
scheme, including specially written software that enabled them to bypass securit 
y controls 
and navigate through credit records to obtain key information. 


Police officials say that the hackers also obtained access codes from pirate bul 
letin board 
systems to make free long distance calls and gain access to various business and 
government 

computers. 


The arrests were the result of a 6 week investigation by the Secret Service and 
the Mount 

Lebanon police. The police were tipped off by parents who were suspicious about 
how their 

son managed to obtain a skateboard valued at $140. 


The Secret Service was also involved in investigations that led to the arrests o 
f several 
hackers in San Francisco and New York last July. 


Secret Service spokesman William Corbett says that although some reports have po 
rtrayed 

the hackers as part of a national crime ring, the cases are unrelated. "It's jus 
t that a few 

of these computers hacking cases came to a head at about the same time," he says 


Federal Legislation enacted in 1984 gives the Secret Service, part of the Depart 
ment of 

the Treasury, a major role in investigating computer crimes. Under the federal C 
omputer 

Fraud and Abuse Act of 1986, computer fraud is a felony that carries a maximum p 
enalty of 

5 years for the first offense, and 10 years for the second. Displaying unauthori 
zed 

passwords on hacking bulletin boards carries a maximum penalty of 1 year in pris 
on for the 

first offense, and 10 years for the second. 


German Teens Crack NASA 


Washington, D.C. -- A group of West German teenagers from the Chaos Computer Clu 
b 

penetrated a NASA network recently, saying they were doing it to "test the secur 
ity." 


What they got into was SPAN Net, a computer network with about 700 notes, which 
is 
actually based at the Goddard Space Center in Maryland. All that's in there is u 
nclassified 
data, space science information, and post-flight data analysis. "Anyone with NAS 
A related 

research can apply for access to SPAN" says a spokesman, who adds that the netwo 
rk runs 

on DEC VAX hardware. "We picked up three attempts to gain access and put in secu 
rity 

precautions so it wouldn't happen." His personal opinion is, "We're happy that t 
hey couldn't 

get back in, and decided to go public." He also added that NASA has many other n 
etworks, 
many of the classified and "probably impenetrable. But I do not want to challeng 
e anybody." 


How'd they get in? Probably they got a West German NASA licensee, which gave the 
ma 
visitor's pass, then they created new passwords with unlimited security for them 
selves, 

after which getting around the network was easy. 
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Switching Systems 


There are currently three different forms of switching systems that are present 
in the 

United States today. Step by Step (SxS), Crossbar, and the Electronic Switching 
System 

(ESS) make up the group. Phreaks have always been a little tentative when it com 
es to 

"doing their work" once they have heard about effects of switching systems on th 
ir hobby. 

After researching this topic, I have found that there really is not that much to 
be worried 

about. Read on, while I share with you information which I have compiled about a 
ll of these 

switching systems and their distinct features. 


O 


The first switching system that was used in the country was called Step by Step. 
This was 
adopted in 1918 by Bell, and until 1978, they had over 53% of all their exchange 
s using Step 

by Step (SxS). This system is known for it's long, confusing train of switches t 
hat are used 

for its step by step switching. 


Step by Step has many disadvantages to phone users. The switch train becomes jam 

med 

fairly often, and it causes calls to be blocked. Also, SxS does not allow the us 
e of DIMF 

dialing. This accounts for some of the areas in the United States that cannot ha 

ve touch 
tone dialing abilities. A tremendous amount of electricity and maintenance needs 
to 
accompany the SxS switching system, which makes it even more impratical. All in 
all, this is 

probably the most archaic switching system around. 


There are a number of ways to see if you are on SxS. You will notice that there 

are no 

pulsing digits after dialing. Most sources say that the phone company will sound 
like many 

typewriters. SxS does not offer features such as speed calling, call forwarding, 
three-way 
calling, call waiting, and other such services. Pay phones on SxS also will want 
your money 

before you receive a dial tone. This adds to the list of disadvantages labeled t 
o that of the 

Step by Step switching systems. 


Another type of switching system that is prevalent in the United States is Cross 
bar. 
Crossbar has been Bell's primary switcher after 1960, and three types of it exis 
ts. 
Number 1 Crossbar (1xB), Number 4 Crossbar (4xB), and the Number 5 Crossbar (5xB 


Jaoob 

Crossbar, a switching matrix is used for all the phones in an area, and when som 
eone calls, 

the route is determined and is met up with the other phone. This matrix is set-u 

p in 
horizontal and vertical paths. Unlike other switching systems, in my research, I 
could not 
come up with any true and definite distinguishing features of the Crossbar switc 
hing 

systems. 


he Electronic Switching System (ESS) is yet another switching system used in th 
United 

tates and the most used of all three switching systems. ESS is an extremely adv 
ced and 

ulti-faced type of switching system, and is feared by marauders of the phone co 
pany 

verywhere. With ESS, your phone company is able to know every digit dialed (inc 
uding 

istakes), who you call, when you called, and how long you were connected. ESS i 
s also 

programmed to print out the numbers of people who make excessive calls to WATS n 
umbers 

(800 services) or directory assistance. This feature of ESS is called 800 Except 
ional 
Calling Report, and has spelled the end of some forms of continuous code hacks t 
o certain 
extenders. ESS can also be programmed to print logs of who called and abused cer 
tain 

numbers as well. Everything is kept track of in its records. 


FoB se Mor 


8 


The aforementioned facts show that ESS has made the jobs of organizations such a 
s the 

FBI, NSA, and other phone company security forces easier. Tracing can be done in 
a matter 

of microseconds, and the result will be conveniently printed out on the monitor 

of a phone 

company officer. ESS is also programmed to pick up any "foreign tones" on the ph 
one line 

such as the many varied tones emulated by boxes. 


ESS can be identified by a few features common in it. The 911 emergency service 

is 

covered in the later versions of ESS. Also, you are given the dial tone first wh 
en using a 

pay phone unlike that of SxS. Calling services like call forwarding, speed calli 
ng, and call 

waiting are also common to ESS. One other feature common to ESS is ANI (Automati 
€ 
Number Identification) for long distance calls. As you can see, ESS is basically 
the zenith 
of all switching systems, and it will probably plague the entire country by the 

early 1990's. 

Soon after, we should be looking forward to a system called CLASS. This switchin 
g system 

will contain the feature of having the number of the person that is calling you 

printed out on 

your phone. 


What have I concluded about these switching systems? Well, they are not good eno 
ugh. I 

know a few people employed by the phone company, and I know for a fact that they 
do not 
have enough time these days to worry about code users, especially in large, metr 
opolitan 
areas. So, I will go out on a limb here, and say that a large portion of people 

will never have 

to worry about the horrors of ESS. 


New Gizmo Can Change Voice Gender 


The most amazing device has turned up in the new Hammacher Schlemmer catalog: th 
e 
telephone voice gender changer. What it does is change the pitch of your voice f 


rom, say, 
soprano to bass -- a most efficient way to dissuade an obscene phone caller just 
as he's 

getting warmed up. That is not the same as running a 45 rpm. record at 33. In di 
gital 


conversion, the pitch can be changed without altering the speed. 


The device runs on a 9-volt batter and attaches to the telephone mouth piece wit 
h a rubber 
coupler that takes but a moment to slip on and off. With the changer switched on 


, says 
Lloyd Gray, a Hammacher Schlemmer technical expert, "the effect is similar to wh 
at you 

hear when they interview an anonymous woman on television and disguise her voice 
by 

deepening it." "It's better for changing a woman's voice to a man's than the oth 
er way 

around," Gray said. A man can use it to raise the pitch of his voice, but he sti 
11 won't sound 


like a woman." 


A man could, however, use the changer to disguise his voice. But with the device 
set on high, 

Gray's voice still could be identified as his own. On low, his normal tenor beca 

me so gravel 

like that the words were unintelligible. 
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AT&T Rates 


WASHINGTON -- American Telephone & Telegraph Co. proposed Tuesday to lower its 


interstate long-distance rates by an average of 3.6% to reflect reduced costs in 
connecting 

to the local telephone network. The largest decrease 6.3% -- would be seen in 
day time 


prices "Because of the need to make those rates more competitive," AT&T said. 


Rates for calls made during evening hours would drop 2.2% and calls made during 
the late 

night and weekends would be cut by 0.8%, the company said. The rate reductions w 
ould take 

effect Jan. 1, if they are approved by the Federal Communications Commission. Re 
acting to 

the proposed price cuts, MCI Communications Corp. and US Sprint Communications C 
o., the 

nation's second-largest and third-largest long distance companies respectively, 
said their 
response would depend on what the FCC finally approves but both said they intend 
ed to 

remain competitive with AT&T. AT&T, the nation's largest long-distance company, 
proposed 
to the FCC that its rates drop as much as $800 million, but AT&T said the exact 
amount will 
depend on the access charges the FCC allows the local telephone companies to col 
lect from 
long distance carriers, which must pay the fees to hook into the phone local net 
work. 


AT&T has challenged the new access rates filed by the regional Bell operating co 
mpanies, 
contending they are more than $1 billion too high. In proposing its new rates, t 
he long- 
distance leader told the FCC it expects local companies' access fees to fall by 
at least 


$200 million -- which would amount to an average rate reduction of less than 1%. 
But the 
company said it believes the FCC will order an additional $600 million in reduct 


ions based on 
AT&T's challenge. 


"We're confident the FCC will recognize that access charges filed by the local t 
elephone 

companies need to be substantially reduced, which would mean more savings for ou 
r 
customers," said Larry Garfinkel, AT&T vice president for marketing. He said the 
company 

filed its proposed rates based on disputed charges because "we wanted to let the 
public 

react ... and further to let the FCC have full knowledge of where we were headin 
g given our 

expectation that we had a valid basis for our dispute." 


AT&T's long-distance rates have fallen by about 34% since the company was stripp 
ed of its 
local operating companies by an antitrust decree nearly four years ago. Since th 
en, phone 

rate payers have been paying a larger share of the 


costs of maintaining the local network through monthly subscriber line charges, 


now $2.60 for residential customers. That has reduced the long-distance companie 
s' share 

of local network expenses, which they pay in the form of access charges. Jack Gr 
ubman, a 

telephone analyst with PaineWebber Inc., said AT&T's proposal targets business c 
ustomers 

because "that's where the competition is and where the better (profit) margins a 
re." In 
addition, it aims to keep the pressure on competition in international calling b 
y extending 

discounts to more customers. Grubman added that, if the company's rate proposal 

is 
approved by the FCC, he would expect no further cuts in AT&T rates in 1988. Wend 
e Lind, 

AT&T administrator of rates and tariffs, said the cuts for business and resident 
ia 
customers are about the same because business cuts are offset by a proposed $128 
million 

increase in AT&T's private line rates. 


AT&T is the only long-distance company whose rates are regulated by the FCC, but 
its 

prices set the pace for the industry. Though AT&T is far larger than any of its 
competitors, 

its market share has been declining since divestiture and the company now says i 
t serves 

about 75 percent of the market. In addition to the reductions in basic long-dist 
ance rates, 
AT&T proposed cutting prices by 5% and 5.7% for its Pro-America calling plans. T 
he 

company also proposed to reduce prices by 2.9 percent for its 800 Service custom 
ers and 

4.4 percent for WATS customers, although it would increase the monthly access li 
ne 

charges for those plans by $3.20 to reflect higher special access charges filed 
by the local 

phone companies. 


US Sprint Operator Service Traffic Increases 40% 


ORLANDO, Fla. -- US Sprint Wednesday announced its long distance operators who b 
egan 

saying, "May I help you?" just five months ago, are now handling 3« million call 
s a month. 


The fiber-optic long-distance carrier, offering the only operator service altern 
ative to 

AT&T has experienced a 40 percent growth in operator service calls since it anno 
unced its 

service July 1. Amanda Weathersby, US Sprint vice president of product marketing 
, said 
Tuesday, "More and more people are taking advantage of our call completion assis 
tance and 

alternative billing arrangements. "Customer surcharges are the same as AT&T with 
the 

added benefit of US Sprint's fiber-optic quality and lower long-distance rates." 
US Sprint 
currently offers person-to-person, station-to-station, call completion and colle 
ct calling. US 

Sprint has announced an agreement with US WEST Service Link that will allow anyo 
ne to 
call on US Sprint and charge their calls to a Regional Bell Operating Co. callin 
g card 
beginning in first quarter 1988. 


"Previously, our operator service was available only on pre-subscribed US Sprint 
phones and 

recently we added operator assistance for US Sprint FON CARD customers," Weather 
sby 

said. "With this new agreement, we'll be able to expand our operator service to 

markets 

such as pay phones, hospitals, and hotels/motels." The newest 24-hour operator s 
ervice 


center in Dallas began operations on Oct. 5. US Sprint's other operator service 
centers are 
in: Cherry Hill, NJ; Atlanta; Lombard, IL and Reno, NV. US Sprint is a joint ven 
ture of 

United Telecommunications Inc. of Kansas City, MO and GTE Corp. of Stamford, Con 
n. 


Pacific Bell Pursuing Calling Card Thief 


SAN FRANCISCO-- (BW) --Pacific Bell is warning consumers to protect their telephon 
e 

calling cards like any other credit card in the wake of a series of frauds by pe 
ople posing as 

phone company employees. A Pacific Bell spokesman says customers in the 213, 805 
and 916 
area codes are being victimized by someone who says he is a telephone company em 

ployee 
investigating calling card fraud. The individual calls people at home at odd hou 
rs, asking for 

their calling card numbers. He then sells the numbers to people who use the numb 
ers to 

make long distance phone calls. 


As recently as Monday of this week, 180 long distance calls were billed to a Sac 
ramento 

area resident who had given his number to the thief just three hours earlier. Ac 
cording to 

Pacific Bell, this kind of scheme and other forms of calling card fraud cost tel 
ephone 


customers nationwide half a billion dollars a year. The company offered these ti 
ps to 
consumers to avoid becoming a victim 


of calling card fraud: 


Never give your calling card number or personal identification number to anyone. 
Any 

telephone company employee with a legitimate need to know the number has access 
to it. 
Treat your calling card like any other credit card. Report its loss immediately 
by calling the 
800 number on the back of the card 800-621-0430. If you receive a suspicious cal 


regarding your telephone calling card, report it by calling the 800 number on th 
e back of 
the card. If you receive a call from someone claiming to be a telephone company 
employee 

and asking for your calling card number, ask for a name and number to call back. 
Then call 

the local Pacific Bell business office to report the incident. 


One suspect was arrested in Southern California last week by a quick thinking cu 
stomer who 
did just that. Pacific Bell immediately contacted the local police department. A 
suspect 
holding seven stolen calling card numbers was arrested minutes later. Pacific Be 
11 and long- 


distance telephone companies will credit customers for calling card charges dete 
rmined to 
be fraudulent. Pacific Bell is a subsidiary of Pacific Telesis Group, a diversif 


ied 
telecommunications corporation based in San Francisco. 


93. The Phreaker's Guide to Loop Lines by The Jolly Roger 


A loop is a wondrous device which the telephone company created as test numbers 
for 
telephone repairmen when testing equipment. By matching the tone of the equipmen 
t with 
the tone of the loop, repairmen can adjust and test the settings of their teleph 
one 
equipment. A loop, basically, consists of two different telephone numbers. Let's 
use A and B 
as an example. Normally if you call A, you will hear a loud tone (this is a 1004 
hz tone), and if 
you call B, the line will connect, and will be followed by silence. 


This is the format of a loop line. Now, if somebody calls A and someone else cal 


ls B 


--Viola!-- 


A and B loop together, and one connection is made. Ma Bell did this so repairmen 


can 
comm 
can 
use 
"Loo 
Assi 
e. 
Anyw 
d an 


unicate with each other without having to call their own repair office. They 


also 


them to exchange programs, like for ANA or Ringback. Also, many CO's have a 


P 


gnment Center". If anyone has any information on these centers please tell m 


ay, that is how a loop is constructed. From 
actual 


this information, an 


loop line. Going back to the A and B example, Note: the tone side an 


sid 
eith 
und 


cute. 


oth 


For 


and 


817 


e can be 
er A or B. Don't be fooled if the phone com 
to be 


As you now know, loops come in pairs of n 
er. 


example: 817-972-1890 


-972-1891 


pany decides to scram 


umbers. Usually, righ 


yone can fin 
d the silent 
ble them aro 


t after each 


Or, to save space, one loop line can be written as 817-972-1890/1. This is not a 


lway 


s true. 


Sometimes, the pattern is in the tens or hundreds, and, occasionally, the number 


S ar 


e 


random. In cities, usually the phone company has set aside a phone number suffix 


tha 


t loops 


ill be used for. Many different prefixes will correspond with that one suffix. 
n Arlington, 

exas, a popular suffix for loops is 1893 and 1894, and a lot of prefixes match 
ith them to 

make the number. 


a 


For Example: 817-460-1893/4 
817-461-1893/4 
817-465-1893/4 


817-467-1893/4 


817-469-1893/4 


...are all loops... 

or a shorter way to write this is: 

817-xxx-1893/4 

xxx= 460, 461, 465, 467, 469 
Note: You can mix-and-match a popular suffix with other prefixes in a city, and 


almost 
always find other loops or test numbers. 


Note: For Houston, the loop suffixes are 1499 and 1799. And for Detroit it's 999 
6 and 
9997. When there are a large number of loops with the same prefix format, chance 
s are 

that many loops will be inter-locked. Using the above example of Arlington loops 
again, (I 

will write the prefixes to save space) 460, 


461, and 469 are interlocked loops. This means that only one side can be used at 


a given time. This is because they are all on the same circuit. To clarify, if 8 
17-461-1893 is 
called, 817-460 and 469-1893 cannot be called because that circuit is being used 


Essentially, interlocked loops are all the same line, but there are a variety of 
telephone 
numbers to access the line. 


Also, if the operator is asked to break in on a busy loop line he/she will say t 
hat the circuit 
is overloaded, or something along those lines. This is because Ma Bell has taken 
the 

checking equipment off the line. However, there are still many rarely used loops 
which can 


be verified and can have emergency calls taken on them. As you have found out, 1 
oops come 

in many types. Another type of loop is a filtered loop. These are loop lines tha 
t the tel co 

has put a filter on, so that normal human voices cannot be heard on either line. 
However, 
other frequencies may be heard. It all depends on what the tel co wants the loop 
to be 

used for. If a loop has gotten to be very popular with the local population or u 
sed frequently 
for conferences, etc. the tel co may filter the loop to stop the unwanted "traff 
ic". Usually, 
the filter will be removed after a few months, though. 


94. How Ma Bell Works by The Jolly Roger 


In this article, I will first describe the termination, wiring, and terminal har 
dware most 

commonly used in the Bell system, and I will include section on methods of using 
them. 


LOCAL NETWORK 


The local telephone network between the central office/exchange and the telephon 
e 
subscribers can be briefly described as follows: 


From the central office (or local exchange) of a certain prefix(es), underground 
area trunks 

go to each area that has that prefix (Usually more than one prefix per area.) At 
every few 
streets or tract areas, the underground cables surface. They then go to the tele 
phone pole 

(or back underground, depending on the area) and then to the subscribers house ( 
or in the 

case of an apartment building or mutli-line business, to a splitter or distribut 
ion box/panel). 

Now that we have the basics, I'll try and go in-depth on the subject. 


UNDERGROUND CABLES 


These are sometimes inter-office trunks, but usually in a residential area they 
are trunk 

lines that go to bridging heads or distribution cases. The cables are about 2-3 
inches thick 

(varies), and are either in a metal or pvc-type pipe (or 


similar). Rarely (maybe not in some remote rural areas) are the cables just ‘alo 
ne' in the 

ground. Instead they are usually in an underground cement tunnel (resembles a sm 
all sewer 

or storm drain.) The manholes are heavy and will say 'Bell system' on them. They 
can be 

opened with a « inch wide crowbar (Hookside) inserted in the top rectangular hol 
e. There 
are ladder rungs to help you climb down. You will see the cable pipes on the wal 
, with the 
blue and white striped one being the inter-office trunk (at least in my area). 
he others are 


= 


oca ines, and are usually marked or color coded. There is almost always a pos 
ted color 
code chart on the wall, not to mention Telco manuals describing the cables and t 


erminals, so 

I need not get into detail. Also, there is usually some kind of test equipment, 
and often 
Bell test sets are left in there. 


BRIDGING HEADS 


The innocent-looking grayish-green boxes. These can be either trunk bridges or b 
ridging 
for residences. The major trunk bridging heads are usually larger, and they have 
the 
‘Western Electric' logo at the bottom, whereas the normal bridging heads (which 
may be 
different in some areas-depending on the company you are served by. GTE B.H.'s 1 
ook 
slightly different. Also, do not be fooled by sprinkler boxes!) They can be foun 
d in just 
about every city. To open a bridging head: if it is locked (and you're feeling d 


estructive), 

put a hammer or crowbar (the same one you used on the manhole) in the slot above 
the top 
hinge of the right door. Pull hard, and the door will rip off. Very effective! I 
f it isn't locked 

(as usual), take a 7/8 inch hex socket and with it, turn the bolt about 1/8 of a 
turn to the 
right (you should hear a spring release inside). Holding the bolt, turn the hand 

le all the way 

to the left and pull out. To Check for a test-set (which are often left by Bell 

employees), go 

inside - First check for a test-set (which are often left by Bell employees). Th 
ere should 

be a panel of terminals and wires. Push the panel back about an inch or so, and 
rotate the 

top latch (round with a flat section) downward. Release the panel and it will fa 
1 all the way 

forward. There is usually a large amount of wire and extra terminals. The test-s 

ets are 

often hidden here, so don't overlook it (Manuals, as well, are sometimes placed 

in the head). 
On the right door is a metal box of alligator clips. Take a few (Compliments of 
Bell.). On 

each door is a useful little round metal device. (Says ‘insert gently' or 'clamp 
gently - do 

not overtighten' etc..) On the front of the disc, you should find two terminals. 
These are 

for your test set. (If you don't have one, dont despair - I'll show you ways to 

make basic 

test sets later in this article). Hook the ring (-) wire to the 'r' terminal; an 
d the tip (+) wire 

to the other. (By the way, an easy way to determine the correct polarity is with 
a l«v LED. 


Tap it to the term. pair, if it doesn't light, switch the poles until it does. W 
hen it lights, 
find the longer of the two LED poles: This one will be on the tip wire (+). Behi 
nd the disc is a 
coiled up cord. This should have two alligator clips on it.. Its very useful, be 
cause you don't 
have to keep connecting and disconnecting the fone (test set) itself, and the cl 
ips work 

nicely. On the terminal board, there should be about 10 screw terminals per side 
. Follow the 

wires, and you can see which cable pairs are active. Hook the clips to the termi 
nal pair, and 
you're set! Dial out if you want, or just listen (If someone's on the line). Lat 
er, I'll show you 
a way to set up a true 'tap' that will let the person dial out on his line and r 
eceive calls as 
normal, and you can listen in the whole time. More about this later... On major 
prefix-area 

bridging heads, you can see 'local loops', which are two cable pairs (cable pair 
= ringttip, a 

fone line) that are directly connected to each other on the terminal board. Thes 
e 'cheap 

loops' as they are called, do not work nearly as well as the existing ones set u 
p in the 

switching hardware at the exchange office. (Try scanning your prefixes (00xx to 99 
XX 
#'s.) The tone sides will announce themselves with the 1008 hz loop tone, and th 
e hang side 
will give no response. The first person should dial the 'hang' side, and the oth 
er person dial 

the tone side, and the tone should stop if you have got the right loop.) If you 
want to find 

the number of the line that you're on, you can either try to decipher the 'bridg 
ing log! (or 

whatever), which is on the left door. If that doesn't work, you can use the foll 
owing: 


ANI # (Automatic Number ID) 

This is a Telco test number that reports to you the number that you're calling f 
rom (It's 

the same, choppy 'Bell bitch' voice that you get when you reach a disconnected n 
umber) 

For the: 


213 NPA - Dial 1223 


408 NPA - Dial 760 


914 NPA - Dial 990 


These are extremely useful when messing with any kind of line terminals, house b 
oxes, etc. 
Now that we have bridging heads wired, we can go on... (don't forget to close an 


d latch the 
box after all... Wouldn't want GE and Telco people mad, now, would we?) 


"CANS" - Telephone Distribution Boxes 
Basically, two types: 


Large, rectangular silver box at the end of each street. 


Black, round, or rectangular thing at every telephone pole. 


Type 1 - This is the case that takes the underground cable from the bridge and r 
uns it to 

the telephone pole cable (The lowest, largest one on the telephone pole.) The bo 
x is always 

on the pole nearest the bridging head, where the line comes up. Look for the 'Ca 
1l before 

you Dig - Underground cable' stickers.. The case box is hinged, so if you want t 
o climb the 
pole, you can open it with no problems. These usually have 2 rows of terminal se 
ts. You could 

try to impersonate a Telco technician and report the number as 'new active' (giv 
ing a fake 

name and fake report, etc.) I don't recommend this, and it probably won't (almos 
t positively 

won't) work, but this is basically what Telco linemen do.) 


Type 2 - This is the splitter box for the group of houses around the pole (Usual 
ly 4 or 5 
houses). Use it like I mentioned before. The terminals (8 or so) will be in 2 ho 
rizontal 
rows of sets. The extra wires that are just ‘hanging there' are provisions for e 
xtra lines to 

residences (1 extra line per house, that's why the insane charge for line #3!) I 
f its the box 

for your house also, have fun and swap lines with your neighbor! 'Piggyback' the 
m and wreak 

havoc on the neighborhood (It's eavesdropping time...) Again, I don't recommend 
this, and 
its difficult to do it correctly. Moving right along... 


APARTMENT / BUSINESS MULTI-LINE DISTRIBUTION BOXES 


Found outside the building (most often on the right side, but not always... Just 
follow the 

wire from the telephone pole) or in the basement. It has a terminal for all the 

lines in the 

building. Use it just like any other termination box as before. Usually says 'Be 

system' or 

similar. Has up to 20 terminals on it (usually.) the middle ones are grounds (fo 

rget these). 

The wires come from the cable to one row (usually the left one), with the other 

row of 

terminals for the other row of terminals for the building fone wire pairs. The r 

ing (-) wire is 

usually the top terminal if the set in the row (1 of 10 or more), and the tip is 


in the clamp/screw below it. This can be reversed, but the cable pair is always 
terminated 

one-on-top-of-each- other, not on the one next to it. (I'm not sure why the othe 
r one is 

there, probably as a provision for extra lines) Don't use it though, it is usual 
ly to close to 

the other terminals, and in my experiences you get a noisy connection. 


Final note: Almost every apartment, business, hotel, or anywhere there is more t 
han 2 lines 
this termination lines this termination method is used. If you can master this t 
ype, you can 

be in control of many things... Look around in your area for a building that use 
s this type, 

and practice hooking up to the line, etc. As an added help, here is the basic 's 
tandard' 
color-code for multi-line terminals/wiring/etc... 


Single line: Red = Ring 


Green = Tip 


Yellow = Ground * 


*Connected to the ringer coil in individual and bridged ringer phones (Bell onl 
y) Usually 
connected to the green (Tip) 


Ring (-) = Red 

White/Red Stripe 

Brown 

White/Orange Stripe 

Black/Yellow Stripe 

Tip (+) = Green (Sometimes yellow, see above.) 
White/Green Stripe 

White/Blue Stripe 


Blue 


w 


lack/White Stripe 
Ground = Black 


Yellow 


RESIDENCE TERMINAL BOX 


Small, gray (can be either a rubber (Pacific Telephone) or hard plastic (AT&T) h 
ousing deal 
that connects the cable pair from the splitter box (See type 2, above) on the po 
le to your 
house wiring. Only 2 (or 4, the 2 top terminals are hooked in parallel with the 
same line) 
terminals, and is very easy to use. This can be used to add more lines to your h 
ouse or add 

an external line outside the house. 


TEST SETS 


Well, now you can consider yourself a minor expert on the terminals and wiring o 
f the loca 
telephone network. Now you can apply it to whatever you want to do.. Here's anot 
her helpfu 
item: 


How to make a Basic Test-Set and how to use it to dial out, eavesdrop, or seriou 
sly tap and 

record line activity. These are the (usually) orange hand set fones used by Telc 
o technicians 

to test lines. To make a very simple one, take any Bell (or other, but I recomme 
nd a good 

Be fone like a princess or a trimline. GTE flip fones work excellently, though 
: fone and 
follow the instructions below. 


— 


Note: A 'black box' type fone mod will let you tap into their line, and with the 
box o, it's as 
if you weren't there. They can receive calls and dial out, and you can be listen 
ing the whole 

time! Very useful. With the box off, you have a normal fone test set. 


Instructions: 


A basic black box works well with good results. Take the cover off the fone to e 
xpose the 

network box (Bell type fones only). The <RR> terminal should have a green wire g 
oing to it 
(orange or different if touch tone - doesn't matter, its the same thing). Discon 
nect the 
wire and connect it to one pole of an SPST switch. Connect a piece of wire to th 
e other pole 
of the switch and connect it to the <RR> terminal. Now take a 10kohm « watt 10% 
resistor 

and put it between the <RR> terminal ad the <F> terminal, which should have a bl 


ue anda 
white wire going to it (different for touch tone). It should look like this: 


Blue wire <F> 


White wire | 


10k Resistor 


Green wire ! <RR> 


SPST 


What this does in effect is keep the hookswitch / dial pulse switch (F to RR loo 
p) open while 
holding the line high with the resistor. This gives the same voltage effect as i 
f the fone was 

'on-hook', while the 10k ohms holds the voltage right above the ‘off hook' thres 
hold 


(around 22 volts or so, as compared to 15-17 or normal off hook 48 volts for nor 
mal 'on- 
hook'), giving Test Set Version 2. 


Another design is similar to the 'Type 1' test set (above), but has some added f 
eatures: 


From > Tip <To Test 


Alligator set 


Clip > Ring <phone 


! x---RRRRR---! 


x< 
[l 


Spst Switch 


Red LOD 0 = Green LED 


O 
Ul 


RRRRR= 1.8k « watt xxxx= Dpst switch 


resistor 


When the SPST switch in on, the LED will light, and the fone will become active. 


The green 
light should be on. If it isn't, switch the dpst. If it still isn't, check the p 
olarity of the line 


and the LEDs. With both lights on, hang up the fone. They should all be off now. 
Now flip 
the dpst and pick up the fone. The red LED should be on, but the green shouldn't 
If it is, 
something is wrong with the circuit. You wont get a dial tone if all is correct. 
When you hook 
up to the line with the alligator clips (Assuming you have put this circuit insi 
de our fone and 
have put alligator clips on the ring and tip wires (As we did before)) you shoul 
d have the 
spst #1 in the off position. This will greatly reduce the static noise involved 
in hooking up to 


a line. The red LED can also be used to check if you have the correct polarity. 
With this 
fone you will have the ability to listen in on all audible line activity, and th 
e people (the 

"eavesdroppers') 


can use their fone as normal. Note that test sets #1 and #2 have true 'black box 
es', and 
can be used for free calls (see an article about black boxes). 


Test Set Version 3 


Using a trimline (or similar) phone, remove the base and cut all of the wire lea 
ds off except 
for the red (ring -) and the green (tip +). Solder alligator clips to the lug. T 
he wire itself is 
'tinsel' wrapped in rayon, and doesn't solder well. Inside the one handset, remo 
ve the light 
socket (if it has one) and install a small slide or toggle switch (Radio Shack's 
micro- 
miniature spst works well). Locate the connection of the ring and the tip wires 
on the PC 
board near where the jack is located at the bottom of the handset. (The wires ar 
e 
sometimes black or brow instead of red and green, respectively). Cut the foil an 
d run 2 
pieces of wire to your switch. In parallel with the switch add a 7 uf 200 VDC ca 
pacitor 
(mylar, silvered mica, ceramic, not an electrolytic). When the switch is closed, 
the handset 


functions normally. With the switch in the other position, you can listen withou 
t being 
heard. 


Note: To reduce the noise involved in connecting the clips to a line, add a swit 
ch selectable 
1000 ohm « watt resistor in series with the tip wire. Flip it in circuit when co 
nnecting, and 
once on the line, flip it off again. (or just use the 'line disconnect' type swi 
tch as in the 
type 2 test set (above)). Also avoid touching the alligator clips to any metal p 
arts or other 

terminals, for I causes static on the line and raises people's suspicions. 


RECORDING 


If you would like to record any activity, use test set 1 or 2 above (for unatten 
ded recording 

of al ine activity), or just any test set if you are going to be there to moni 
tor when they 

are dialing, talking, etc. Place a telephone pickup coil (I recommend the Becoto 
n T-5 TP coil 
or equivalent) onto the test set, and put the TP plug into the mic. jack of any 
standard tape 

recorder. Hit play, rec, and pause. Alternate pause when you want to record (I d 
on't think 

anyone should have any difficulty with this at all...) Well, if you still can't 
make a test set or 

you don't have the parts, there's still hope. 


Alternate methods: 


ind a bell test set in a manhole or a bridging head and ‘Borrow it indefinitely 


- 


Test sets can be purchased from: 


Techni-Tool 


5 Apollo Road 
Box 368 
Plymouth Meeting PA., 19462 


Ask for catalog #28 


They are usually $300 - $600, and are supposed to have M-F dialing capability as 
well as TT 


dialing. They are also of much higher quality than the standard bell test sets. 
If you would 
like to learn more about the subjects covered here, I suggest: 


Follow Bell trucks and linemen or technicians and ask subtle questions. also try 
611 (repair 
service) and ask questions.. 


Explore your area for any Bell hardware, and experiment with it. Don't try somet 
hing if you 

are not sure what you're doing, because you wouldn't want to cause problems, wou 
ld 

you? 


95. Getting Money out of Pay Phones by The Jolly Roger 


I will now share with you my experiences with pay telephones. You will discover 


that it is possible to get money from a pay phone with a minimum of effort. Theo 
ry: Most 

pay phones use four wires for the transmission of data and codes to the central 
office. 

Two of them are used for voice (usually red and green), one is a ground, and the 
last is used 

with the others for the transmission of codes. 


It is with this last wire that you will be working with. On the pay phone that I 


usually did 
this to, it was colored purple, but most likely will be another color. What you 


wi do is simply 


find a pay phone which has exposed wires, such 


that one of them can be disconnected and connected at ease without fear of disco 


very. Yo 


u 


will discover that it is usually a good idea to have some electrical tape along 
with you and 
S 
e 


ome tool for cutting this tape. Through trial and error, you will disconnect on 
wire at a 


ime starting with the wires different than green and red. You do want a dial to 
ne during 
this operation. What you want to disconnect is the wire supplying the codes to t 
he 
telephone company so that the pay phone will not get the 'busy' or 'hang-up' com 
mand. 
Leave this wire disconnected when you discover it. What wi happen: Anytime tha 
t someone 
puts any amount of money into the pay phone, the deposit will not register with 
the phone 
company and it will be held in the 'temporary' chamber of the pay phone. Then, ( 
a day later 
or so) you just come back to the phone, reconnect the wire, and click the hook a 
few times 


and the phone will dump it all out the chute. (What is happening is that the 'ha 


ng-up' code 


that the phone was not receiving due to the wire being disconnected suddenly get 
s the code 


and 


dumps its' 'temporary' storage spot.) You can make a nice amount of money this w 


ay, but 


remember that a repairman will stop by every few times it is reported broken and 


repair 
so check 


IË; 


it at least once a day. Enjoy and have fun.. Many phones I have done th 


is to, and it 


works we 


with each.. 


96. Computer Based PBX by The Jolly Roger 


To get a better understanding of what a pbx can do, here are a few basic fundame 


ntals. The 
modern pbx is a combined computer, mass storage device, and of course a switchin 


g system 
that can 


Produce itemized, automated billing procedures, to allow the identification and 
management of toll calls. [hahaha] 


Combine daytime voice grade communication circuits into wideband data channels f 


or night 
time high 


speed data transfers. 


Handles electronic mail [including office memos]. 


Combine voice channels into a wideband audio/visual conference circuit, with the 
ability to 
xfer and capture slides, flipcharts, pictures of any kind. 


Both the external and internal calling capacity of the pbx system must be carefu 


lly 


considered because many business operations run a very high ratio of internal st 


ation to 


station dialing and a low capacity system will not handle the requested traffic 


load. A 


critical factor is the number of trunks and the central office facilities that a 


re used for 


outside connections. Another is the number of junctions or [links] that make up 


the internal 


calling paths. To understand the services available on a typical computer run pb 


x it is 
necessary 


n switching 
network al 


ime-divisi 


to introduce the subject of time division switching. In a time divisio 


l connections are made via a single common bus called (of course) a 't 
on 


bus'. Every line trunk that requires a connection with another is provided with 


a port 


circuit. All port circuits have access to the time division bus through a time d 
ivision switch. 


[when two ports require connection, their time division switches operate at a ve 
ry high 

frequency (16,000 times per second.) This technique, which is called 'speech sam 
pling', 

allows many simultaneous connections over the same time division bus. Each conne 
ction is 
assigned a time interval, the 'time slot', and the number of time slots identifi 
es the number 

of simultaneous connections among ports.] The next critical item is circuit pack 
s. The 
system elements that we will be describing in future tutorials [lines/trunks/swi 
tches, 
memory and control] are contained on plug in circuit packs. Each line circuit pa 
ck contains a 
number of lines, in example, four. But the assignment of station numbers to actu 
al phone 
line circuits is flexible. The system memory is contained in circuit packs which 
provide the 
call processing functions. The circuit packs are held in small frames called 'ca 
rriers'. Within 

each carrier, the circuit packs are plugged into positions: the 'slots'. Every c 
ircuit can be 

addressed by, say a five digit number which tells its location by carrier-slot-c 
LECU Esus 
starting to get the idea?] There can be three types of carriers in a modern pbx 
system: 


O line carriers 
0 trunk carriers 
O control carriers 


The line carriers contain station lines. In AT&T's "dimension" model, for exampl 
e, a total of 

52 to 64 lines are provided. The trunk carriers contain slots for 16 trunk circu 
it packs. The 
control carrier includes processor, memory, control circuitry, data channels for 
attendant 

console control and traffic measurement outputs. Pbx systems will directly refle 
ct the 

types of services offered at the c.o. 


o ccsa 
o ccis 


o picturephones [sooner than you think my phriends] 


Common control switching arrangements (ccsa) permit any unrestricted telephone s 
tation to 
call any other internal or external system station by using the standard seven d 


igit number. 
Alternate routing is a feature of ccsa service the inter-facility, alternate rou 
ted calling 
paths are accomplished at the telephone company central office level, not at the 
pbx level. 
A system of interest to large scale telephone users is common channel interoffic 
e signaling 
ccis. Typically, this technique employs common channels to carry all inter-facil 
ity signaling 
instructions: dial pulses, on hook (idle), off hook (busy),and so on, between tw 
o switching 
centers. [getting warm]. Ccis replaces older methods of interoffice signaling su 
ch as ‘in 
band' and ‘out of band' techniques. By the way, real phreaks are selling their b 
oxes to 
idiots who still think they're worth a lot...the former (in band) transmits sign 
aling data 
within the normal conversation bandwidth. Itļs shortcoming is that false informati 
on may 
be transmitted due to unique tone or noise combinations set up in the talking pa 
th. [this is 
the official reasoning]. Out of band signaling techniques placed the interoffice 
data in 
special channels, generally adjacent to and immediately above the voice path. To 
preserve 
interchannel integrity, out of band signaling requires very efficient filtering 
or greater 
"band guard' separation between channels. 


97. PC-Pursuit Port Statistics by PC-Pursuit Users 


Introduction: 


The last 30 days of PC-Pursuit have been extremely controversial. Users and ex-u 
sers have 

demanded accurate statistics, and Telenet has provided us with very little. And 
the data 

that was provided is questionable. Well, here is some data that is guaranteed to 
be accurate 

and make Telenet scream. If you wish to update this data on your own, we will te 
ll you how 
ater in this text. The following chart consists of all the direct Telenet addre 
sses of the 

PC-Pursuit city nodes and the total number of modems on each node. Here is what 
the data 

means: 


NJNEW/3 2011 .12 56 
! ! ! ! \-- Total Number of Modems in NJNEW 
! ! ! \- Last Working Suffix of Address sequence. 


! ! \= Direct Telenet Address Prefix. 


! \--- Baud Rate of This Port is 300. 


\ Mnemonic. 


Please note that there are several perfectly legal ways to connect to a PC-Pursu 
it port such 
as NJNEW/3: 


Ways To Connect to NJNEW/3: 
C D/NJNEW/3,PCP10000,<password> [HUNT] 
C 2011,PCP10000,<password> [HUNT] 


C 2011.10,PCP10000,<password> [NON HUNT] 


The first, is self explanatory. The second does the same thing as the first, onl 
y that it is 
slightly faster and gives the user much greater flexibility. The third is an exa 
mple the 
flexibility, because a request is made to connect to the tenth, and only the ten 
th, modem on 
the NJNEW/3 port. By simply attempting to connect to every single modem in the 2 


011 

chain, we were able to count the number of modems on each port and come up with 
the 
following charts which were extracted on June the twenty ninth of the year 1989: 


Rotary PortDirect AddressMax. RangeCity TotalRotary PortDirect AddressMax. 
RangeCity TotalNJNEW/32011.1256CAOAK/34155.416 /12201301.4 /12415216.8 
/2420122.4 /2441511.4DCWAS/3202115.646CAPAL/3415106.412 /12202116.24 
/12415224.8 /24202117.16 
/24NONENONECTHAR/ 3NONENONE8CASFA/3415215.620 /12203120.8 
/12415217.10 /24NONENONE /24 41523.4WASEA/320617.430O0RPOR/350320.28 
/1220619.22 /1250321.6 /2420621.4 
/24NONENONENYNYO/3212315.422AZPHO/360222.420 /12212316.14 /1260223.12 
/2421228.4 /2460226.4CALAN/3213412.840MNMIN/3612120.422 /12213413.28 
/12612121.14 /2421323.4 /2461222.4TXDAL/3214117.630MABOS/3617311.432 
/12214118.22 /12617313.20 /2421422.4 
/2461726. 8PAPHI/3215112.636TXHOU/3713113.842 /122155.22 /12713114.24 
/2421522.8 /2471324.10HCLE/321620.426CACOL/371423.418 /1221621.18 


/127144.1 /24216120.4 /2471424.4CODEN/ 3303114. 440CASAN/3714119.420 
/12303115.18 /12714213.12 /2430321.22 

/24714124. 4FLMIA/3305120.628CASDI/3714102.422 /12305121.18(619) /12714210.14 
05122.4 /24714121.4ILCHI/3312410.840UTSLC/380120.422 /12312411.28 
0121.14 /2431224.4 /2480112.4MIDET/3313214.630FLTAM/381320.418 
13216.18 /1281321.1 /2431324.6 

13124. 4MOSLO/33145.416MOKCI/3816104.420 /12314421.8 /12816221.12 
1420.4 /24816113.4GAATL/3404113.832CAGLE/3NONENONE?? /12404114.20 
1821.18 /2440422.4 /24NONENONECASJO/3408111.434CASAC/39167.416 
0821.26 /1291611.8 /24408110.4 
1612.4WIMIL/341420.424NCRTIP/391920.420 /1241421.16 /1291921.12 
14120.4 /24919124.4NOTE: CASAC/3, CASAC/24 were estimated. 


SS Ts SR SS SS 
KIPE Fa DI KS FD 
ANNARANDNNBA 


PE Pees a 


/244] 


PC-Pursuit Modems Statistics Chart 
Number of Modems - 01/29/89 


Mnemonic30012002400TotalNJNEW1240456DCWAS6241646CTHAR0808WASEA422430NYNY0414422C 
ALAN828440TXDAL622432PAPHI6228360HCLE418426CODE4182244FLMIA618428ILCHI828440MIDE 
T618630MOSL048416GAATL820432CASJ0426434WIMIL41 6424CAOAK48 41 6APAL48012CASFA610420 
ORPOR2 608AZPHO12420MNMIN414422MAB0S420832TXHOU8241042CACOL410418CASAN412420CASDI 
414422UTSLC414422FLTAM410418MOKCI412420CAGLE418426CASAC4841 6NRTP412420Totall6656 
21708 98Average4 .882352916«29412526.411765 


I think the statistics basically speak for themselves. I am sure there will no d 
oubt be 
hundreds of people who will not smile at the number of specific kinds of ports s 
upported, 
not to mention the number of 'dead' or 'down' modems you will find when you veri 
fy the 
totals. Usually, 2% to perhaps 10% of the modems are 'dead' with specific ones r 
epeatedly 


Fg 


failing week after week. 


History Of This Collection: 


Almost a year ago a small selected group of devoted individuals got together to 

discuss 

problems with the PC-Pursuit Network, in the middle of our discussions a questio 

n was asked 

as to how the network really processes our calls. This was intended to help us a 

ssess SET 

commands and other such matters. When the address hypothesis was offered we quic 

kly 

set out to prove it. It was proved in about 3 minutes with the discovery of 2011 
(First try 

was xxxl). The data has continually been collected and analyzed ever since, but 

until now, 

has never been mass released. 


A small group of teen age hackers discovered several interesting things that can 
be done 
with these addresses many of which will not be discussed here short of mentio 


ning that 

these ports connected to via these addresses are not limited to PC-Pursuiters. Y 
ou can, 

however, fight "dead" dialout modems in cities via the address method. Dead mode 

ms can be 
located in about 10 seconds (faster than Telenet), and can either be reported or 
skipped 

past by the user connecting to the next modem in the sequence after the "dead" o 

ne. (Note: 

Say 2011.3 is dead, connect to 2011.4 and you will be past it. If 2011.4 is busy 
, go to 2011«. 

The reader should notice 2011.3 is the same as 2011C.) 


The most interesting value of these addresses is that one can count the number o 
f ports 

that Telenet keeps so secret (Grin). When there were only 28 cities in operation 
there 

were an average of 2.7 300 baud, 9.4 1200 baud, and 2« 2400 baud modems in each 
city. 

Some cities had as little as 2 modems on a port and as many as 12. Only recently 
has the 

number of modems per city begun to jump. 


How To Update The Count Yourself: 


An ID is not required to "request" one of these ports, thus the tallying can be 
done any 

time of day by simply typing the number at the @ prompt. Here is an example with 
four 

modems (NJNEW/24): 


@20122.1 


201 22A REFUSED COLLECT CONNECTION 19 80 


@20122.2 


201 22B REFUSED COLLECT CONNECTION 19 80 


@20122.3 


201 22C REFUSED COLLECT CONNECTION 19 80 


@20122.4 


201 22D REFUSED COLLECT CONNECTION 19 80 


@20122« 


201 22E ILLEGAL ADDRESS 19 80 


The reader should be aware that PC-Pursuit ports always respond with '19 80'. Do 
not 

confuse it with '19 00', which are not PC-Pursuit ports. In the above example we 
know there 

are four ports because the forth was the last existing port before we encountere 
d the 

‘ILLEGAL ADDRESS.' There are several ways to signify that you have gone one beyo 
nd the 

end of the ports: 


XXX xxx ILLEGAL ADDRESS 19 80 


xxx xxx NOT OPERATING 19 80 


The request freezes (Note: Issue a BREAK then D <C/R> to abort the attempt 
yielding 'ATTEMPT ABORTED'.) 


You should be aware that modems which are out of order in the middle of the sequ 
ence can 

respond with 'NOT OPERATING' or may freeze the request. You should also note tha 
t 
when updating the existing list, all you need to do is try to request the next m 
odem beyond 

the end as of the last check. 


Finding Newly Added Ports: 


Many ports have not yet been installed; hence, we do not yet know the addresses. 
New 

ports may be found by entering the first three digits of the area code and appen 
ding (1-29, 
101-129, 201-229, 301-329, etc.) until the 'REFUSED COLLECT CONNECTION 19 80' 
appears. Once this is found, simply log onto the port address with your ID and R 
/V dial some 
silly series of digits, disconnect the port, then connect to the PC-Pursuit mnem 
onic you 
think it might be and R/V redial the last number. If the numbers match, you foun 
dait: 


98. Pearl Box Plans by The Jolly Roger 


The Pearl Box: Definition - This is a box that may substitute for many boxes whi 
ch produce 

tones in hertz. The Pearl Box when operated correctly can produce tones from 1-9 
999hz. 

As you can see, 2600, 1633, 1336 and other crucial tones are obviously in its so 
und 

spectrum. 


Materials you will need: 


Cl, C2:«mf or «uf ceramic disk capacitors 


(Cee NPN transistor (2N2222 works best) 
Serk Normally open momentary SPST switch 
SP Arete SPST toggle switch 

Blerers Standard 9-Volt battery 

Riles oa% Single turn, 50k potentiometer 

ROS ents Single turn, 100k potentiometer 
Rausis Single turn, 500k potentiometer 

R4 sont bare Single turn, 1Meg potentiometer 


SPKR...Standard 8-ohm speaker 
Tenisas Mini transformer (8-ohm works best) 
Misc...Wire, solder, soldering iron, PC board or perfboard, box to contain the c 


ompleted 
unit, battery clip 


Instructions for building Pearl Box: 


Since the instruction are EXTREMELY difficult to explain in words, you will be g 
iven a 
schematic instead. It will be quite difficult to follow but try it any way. 


(Schematic for The Pearl Box) 


CICA 

bel, 33 

+ + ----- +T1 
DT 

b De @SSs==55 |! + 
! gl ! +-S1- 

L @----- S2---+ ! SPKR 
!o tot +---- 

| B1 ! 

Io ot ol 

| +------- + 

!R1 R2 R3 R4! 


AAAA AA AA AA 


Now that you are probably thoroughly confused, let me explain a few minor detail 


s. The 
potentiometer area is rigged so that the 
le of the 


left pole is connected to the center po 


potentiometer next to it. The middle terminal of Tl is connected to the piece of 


wire that 
runs down to the end of the battery. 


Correct operation of The Pearl Box: 


You may want to get some dry-transfer decals at Radio Shack to make this job a 1 


ot easier. 


Also, some knobs for the tops of the potentiometers may be useful too. Use the d 


ecals to 


calibrate the knobs. R1 is the knob for the ones place, R2 is for the tens place 


, R3 if for the 


hundreds place and R4 is for the thousands place. S1 is for producing the all th 


e tones and 
S2 is for power. 


Turn on the power and adjust the knobs for the desired tone. 


(Example: For 2600 hz-R1=0:R2=0:R3=6:R4=2) 


om 


recheck 
1l connections and schematic. 


oO 


fe’) 


99. The Phreak file by The Jolly Roger 


202 282 3010 UNIV. OF D.C. 
202 553 0229 PENTAGON T.A.C. 


202 635 5710 CATHOLIC UNIV. OF AMERICA 


202 893 0330 DEFENSE DATA NETWORK 


202 893 0331 DEFENSE DATA NETWORK 


202 965 2900 WATERGATE 


203 771 4930 TELEPHONE PIONEERS 


206 641 2381 VOICE OF CHESTER 
212 526 1111 NEW YORK FEED LINE 


212 557 4455 SEX HOT LINE 


it the push-button switch and VIOLA! You have the tone. If you don't have a ton 


213 


415 


505 


512 


799 


934 


976 


986 


541 


547 


576 


664 


393 


667 


939 


221 


248 


642 


883 


472 


5017 


9090 


2727 


1660 


2462 


6801 


6061 


3321 


1000 


4280 


1600 


5519 


8818 


2160 


6828 


2181 


ABC NY FEED LINE 


DIAL-AN-IDIOT 


P; 


S 


S 


D.A. 


TOCK QUOTES 


TOCK MARKET REPORTS 


NAVY SHIPS INFO 


" 


" 


NEWS FOR THE BLIND 


" 


" 


LOTTERY INFO 


" 


" 


NUCLEAR COMMISSION 


1ST NATIONAL BANK 


EARTHQUAKE REPORT 


" 


" 


" 


" 


512 


512 


512 


512 


512 


516 


619 


619 


703 


703 


703 


703 


703 


703 


703 


714 


716 


800 


800 


800 


800 


800 


800 


800 


800 


800 


800 


800 


800 


800 


472 


472 


472 


472 


870 


794 


748 


748 


331 


334 


354 


737 


835 


861 


861 


974 


475 


222 


223 


227 


248 


321 


323 


323 


323 


325 


325 


344 


368 


424 


4263 


9833 


9941 


9941 


2345 


1707 


0002 


0003 


0057 


6831 


8723 


2051 


0500 


7000 


9181 


4020 


1072 


0555 


3312 


5576 


0151 


1424 


3026 


4756 


7751 


4112 


6397 


4000 


6900 


9090 


WEIRD RECORDING 
INSERT 25 CENTS 


SPECIAL RECORDING 


LOOP LINE 

MCI (5 DIGITS) 

WASH. POST 

COMPEL INC. 
METROPHONE (6 DIGITS) 
VALNET (5 DIGITS) 


SPRINT (6/8 DIGITS) 


SPRINT (6/8 DIGITS) 
CA. MAINFRAME 


N.Y. DEC-SYSTEM 


RESEARCH INSTITUTE 
CITIBANK 

EASTERN AIRLINES 
WHITE HOUSE PRESS 
FLIGHT PLANES 
TEL-TEC (6 GIGITS) 
MOTOROLA DITELL 
MCI MAINFRAME 
EASYLINK 

FYI 


MSG SYSTEM 


SKYLINE ORDER LINE 


RONALD REAGAN'S PRESS 


800 


800 


800 


800 


800 


800 


800 


800 


800 


800 


800 


800 


800 


800 


800 


914 


424 


438 


521 


521 


526 


527 


621 


621 


621 


621 


631 


821 


828 


858 


882 


997 


9096 


9428 


2255 


8400 


3714 


1800 


3026 


3028 


3030 


3035 


1146 


2121 


6321 


9313 


1061 


1277 


WHITE HOUSE SWITCH 


ITT CITY CALL SWITCHING 


AUTONET 
TRAVELNET (8 DIGITS) 
RCA MAINFRAME 
TYMNET 


SPECIAL OPERATOR 


wow 
wow 


wow 


VOICE STAT 


BELL TELEMARKETING 


XEROX $ 
RECORD-A-VOICE 


AT&T STOCK PRICES 


wow 


445 


950 


950 


950 


950 


950 


950 


2864 


1000 


1022 


JERRY BROWN 


SPRINT 


MCI EXECUNET 


1033 


1044 


1066 


1088 


US TELEPHONE 


ALLNET (6 DIGITS) 


LEXITEL 


SKYLINE (6 DIGITS) 


PHONE # | DESCRIPTION/CODE 


201-643-2227 | CODES:235199, 235022 AND 121270 


800-325-4112 


800-547-1784 


800-424-9098 


800-424-9099 


202-965-2900 


800-368-5693 


202-456-7639 


202-545-6706 


202-694-0004 


WESTERN UNION 


CODES:101111, 350009 AND 350008 


TOLL FREE WHITE HS. 


DEFENSE HOT LINE 


WATERGATE 


HOWARD BAKER HOTLINE 


REAGANS SECRETARY 


PENTAGON 


PENTAGON MODEM 


| 
201-932-3371 | REUTERS 
| 
800-325-2091 | PASSWORD: GAMES 
| 
800-228-1111 | AMERICAN EXPRESS 
| 
617-258-8313 | AFTER CONNECT PRESS CTRL-C 


| 
800-323-7751 


PASSWORD: REGISTER 


| 
800-322-1415 


CODES:266891, 411266 AND 836566 (USED BY SYSOP) 


The following 800 #'s have been collected however no codes have been found yet! 
if you 
hack any please let me know... 


phone # | codes: 


800-321-3344 Coral Gta cat 


800-323-3027 Carter er ater atars 


800-323-3208 ALERE ater eters 


800-323-3209 TEET P waters 


800-325-7222 | 2222272222? 


800-327-9895 | 22222222222 


800-327-9136 CELLET EE RER 


800-343-1844 Pata a Area ates 


800-547-1784 | 2222222222? 


800-547-6754 cetera rarer tars 


800-654-8494 ALERIA 


800-682-4000 PERETE ERE RE 


800-858-9000 TELER IER aED 


800 numbers with carriers. 
800-323-9007 
800-323-9066 
800-323-9073 
800-321-4600 


800-547-1784 


1-800 numbers of the government. 


800-321-1082:NAVY FINANCE CENTER. 


800-424-5201:EXPORT IMPORT BANK. 


800-523-0677:ALCOHOL TOBACCO AND. 


800-532-1556:FED INFORMATION 


CNTR1-1082:NAVY FINANCE CENTER. 


800-424-5201:EXPORT IMPORT BANK. 


800-523-0677: 


800-532-1556: 


800-325-4072: 


800-325-4095: 


800-325-4890: 


800-432-3960: 


800-426-5996: 


Directory of 


800-432-3960: 


800-426-5996: 


Directory of 


301-234-0100: 


202-456-1414: 


202-545-6706: 


202-343-1100: 


714-891-1267: 


ALCOHOL TOBACCO AND. 


FED 


INFORMATION CNTR. 


COMBAT & ARMS SERVICE. 


COMBAT SUPPORT BRANCH. 


ROPD USAR COMBAT ARMS. 


SOCIAL SECURITY. 


PUGET NAVAL SHIPYARD. 


toll free numbers. 


SOCIAL SECURITY. 


PUGET NAVAL SHIPYARD. 


toll 


BAL 


free numbers. 


TIMORE ELECTRIC. 


WHITE HOUSE. 


PENTAGON. 


EPA. 


DIAL-A-GEEK. 


714-897-5511: TIMELY. 


213-571-6523:SATANIC MESSAGES. 


213-664-7664:DIAL-A-SONG. 


405-843-7396:SYNTHACER MUSIC. 


213-765-1000:LIST OF MANY NUMBERS. 
512-472-4263:WIERD. 
512-472-9941: INSERT 25. 
203-771-3930:PIONEERS. 
213-254-4914:DIAL-A-ATHIEST. 
212-586-0897:DIRTY. 
213-840-3971: HOROWIERD 
203-771-3930:PIONEERS 
471-9420, 345-9721, 836-8962 
836-3298, 323-4139, 836-5698 
471-9440, 471-9440, 471-6952 
476-6040, 327-9772, 471-9480 
800-325-1693, 800-325-4113 


800-521-8400:VOICE ACTIVATED 


213-992-8282:METROFONE ACCESS NUMBER 


617-738-5051:PIRATE HARBOR 
617-720-3600: TIMECOR #2 
301-344-9156:N.A.S.A PASSWORD: GASET 


318-233-6289:UNIVERSITY LOUISIANA 


i) 


13-822-2112:213-822-3356 


i) 


13-822-1924:213-822 3127 


i) 


13-449-4040:TECH CENTER 


i) 


13-937-3580: TELENET 


1-800-842-8781 


1-800-368-5676 


1-800-345-3878 


212-331-1433 


213-892-7211 


213-626-2400 


713-237-1822 


713-224-6098 


713-225-1053 


713-224-9417 


818-992-8282 


1-800-521-8400 


After entering the sprint code, and, C+Destination number. Then enter this 


number: 205#977#22", And the main tracer for sprint will be disabled. 


215-561-3199/SPRINT LONG DISTANCE 
202-456-1414/WHITE HOUSE 


011-441-930-4832/QUEEN ELIZABETH 


916-445-2864/JERRY BROWN 
800-424-9090/RONALD REAGAN'S PRESS 
212-799-5017/ABC NEW YORK FEED LINE 


800-882-1061/AT & T STOCK PRICES 


212-986-1660/STOCK QUOTES 


213-935-1111/WIERD EFFECTS! 


512-472-4263/WIERD RECORDING 


212-976-2727/P.D.A. 


619-748-0002/FONE CO. TESTING LINES 


900-410-6272/SPACE SHUTTLE COMM. 


201-221-6397/AMERICAN TELEPHONE 


215-466-6680/BELL OF PENNSYLVANIA 


202-347-0999/CHESAPEAKE TELEPHONE 


213-829-0111/GENERAL TELEPHONE 


808-533-4426/HAWAIIAN TELEPHONE 


312-368-8000/ILLINOIS BELL TELEPHONE 


317-265-8611/INDIANA BELL 
313-223-7233/MICHIGAN BELL 


313-223-7223/NEVADA BELL 


207-955-1111/NEW ENGLAND TELEPHONE 


201-483-3800/NEW JERSEY BELL 


212-395-2200/NEW YORK TELEPHONE 


515-243-0890/NORTHWESTERN BELL 
216-822-6980/OHIO BELL 


206-345-2900/PACIFIC NORTHWEST BELL 


213-621-4141/PACIFIC TELEPHONE 


205-321-2222/SOUTH CENTRAL BELL 
404-391-2490/SOUTHERN BELL 


203-771-4920/SOUTHERN NEW ENGLAND 


314-247-5511/SOUTHWESTERN BELL 


414-678-3511/WISCONSIN TELEPHONE 
800-327-6713/UNKNOWN ORIGIN 
303=232-8555/HP3000 
315-423-1313/DEC-10 
313-577-0260/WAYNE STATE 
512-474-5011/AUSTIN COMPUTERS 
516-567-8013/LYRICS TIMESHARING 
212-369-5114/RSTS/E 
415-327-5220/NEC 
713-795-1200/SHELL COMPUTERS 
518-471-8111/CNA OF NY 
800-327-6761/AUTONET 
800-228-1111/VISA CREDIT CHECK 
713-483-2700/NASUA 
213-383-1115/COSMOS 


408-280-1901/TRW 


404-885-3460/SEARS CREDIT CHECK 
414-289-9988/AARDVARK SOFTWARE 
919-852-1482/ANDROMEDA INCORPORATED 
213-935 72922) ARTSCI 
714-627-9887/ASTAR INTERNATIONAL 


415-964-8021/AUTOMATED SIMULATIONS 


503-345-3043/AVANT GARDE CREATIONS 
415-456-6424/BRODERBUND SOFTWARE 
415-658-8141/BUDGE COMPANY 


714-755-5392/CAVALIER COMPUTER 


801-753-6990/COMPUTER DATA SYSTEMS 


213-701-5161/DATASOFT INC. 


213-366-7160/DATAMOST 
716-442-8960/DYNACOMP 
213-346-6783/EDU-WARE 


800-631-0856/HAYDEN 


919-983-1990/MED SYSTEMS SOFTWARE 
312-433-7550/MICRO LAB 


206-454-1315/MICROSOFT 


301-659-7212/MUSE SOFTWARE 
209-683-6858/ON-LINE SYSTEMS 
203-661-8799/PROGRAM DESIGN (PDI) 


213-344-6599/QUALITY SOFTWARE 


303-925-9293/SENTIENT SOFTWARE 


702-647-2673/SIERRA SOFTWARE 


Ne} 


16-920-1939/SIRIUS SOFTWARE 


i) 


15-393-2640/SIR-TECH 


as 


15-962-8911/SOFTWARE PUBLISHERS 


ad 


15-964-1353/STRATEGIC SIMULATIONS 


217-359-8482/SUBLOGIC COM. 


206-226-3216/SYNERGISTIC SOFTWARE 


Here are a few tips on how not to get caught when using MCI or other such servic 
es: 


Try not to use them for voice to voice personal calls. Try to use them for compu 
ter calls 
only. Here is why: 


MCI and those other services can't really trace the calls that come through the 
lines, they 
can just monitor them. They can listen in on your calls and from that, they can 
get your 

name and other information from the conversation. They can also call the number 
you 

called and ask your friend some questions. If you call terminals and BBS'S then 
it is 

much harder to get information. For one thing, most sysops won't give these dude 
s that 

call any info at all or they will act dumb because they PHREAK themselves! 


Try to find a sine-wave number. Then use an MCI or other service to call it. You 
will hear a 
tone that goes higher and lower. If the tone just stops, then that code is being 


monitored and you should beware when using it. 


If you do get caught, then if you think you can, try to weasel out of it. I have 
heard many 

stories about people that have pleaded with the MCI guys and have been let off. 
You will 

get a call from a guy that has been monitoring you. Act nice. Act like you know 
it is now 

wrong to do this kind of thing..... just sound like you are sorry for what you di 
d. (If you get a 

call, you probably will be a little sorry!) Otherwise, it is very dangerous!!!!! 
!! (Very with a 

capital V!) 


100.Red Box Plans by The Jolly Roger 


Red boxing is simulating the tones produced by public payphones when you drop yo 
ur money 

in. The tones are beeps of 2200Hz + 1700Hz a nickle is 1 beep for 66 millisecond 
s. A dime is 


2 beeps, each 66 milliseconds with a 66 millisecond pause between beeps. A quart 
er is 5 
beeps, each 33 milliseconds with a 33 millisecond pause between beeps. 


There are two commonly used methods being used by Phreaks to make free calls. 


An electronic hand-held device that is made from a pair of Wien-bridge oscillato 
rs with the 
timing controlled by 555 timing chips. 


A tape recording of the tones produced by a home computer. One of the best compu 
ters to 

use would be an Atari ST. It is one of the easier computers to use because the r 
ed box 

tones can be produced in basic with only about 5 statements. 


101.RemObS by The Jolly Roger 


Some of you may have heard of devices called Remobs which stands for Remote Obse 
rvation 

System. These Devices allow supposedly authorized telephone employees to dial in 
to them 


£ 


from anywhere, and then using an ordinary touch tone fone, tap into a customer's 


ine ina 
special receive only mode. [The mouthpiece circuit is deactivated, allowing tota 
y silent 


observation from any fone in the world (Wire tapping without a court order is ag 
ainst the 
law) ] 


How Remobs Work 


Dial the number of a Remob unit. Bell is rumored to put them in the 555 informat 
ion 

exchanges, oron special access trunks [Unreachable except via blue box]. A tone 
wil 

b 


j then 
e heard for approximately 2 seconds and then silence. You must key in (In DTMF) 
a2to5 
digit access code while holding each digit down at least 1 second. If the code i 
s not entered 

within 5 or 6 seconds, the Remob will release and must be dialed again. If the c 
ode is 
supposedly another tone will be heard. A seven digit subscriber fone number can 
then be 

entered [The Remob can only handle certain 'exchanges' which are prewired, so us 
ually one 

machine cannot monitor an entire NPA]. The Remob will then connect to the subscr 
ibers 


line. The listener will hear the low level idle tone as long as the monitored pa 
rty is on hook. 
As the monitored party dials [rotary or DTMF], the listener would hear [And Reco 
rd] the 

number being dialed. Then the ENTIRE conversation, datalink, whatever is taking 
place, all 
without detection. There is no current box which can detect Remob observation, s 
ince it is 

being done with the telephone equipment that makes the connection. When the list 
ener is 
finished monitoring of that particular customer, he keys the last digit of the a 
ccess code to 
disconnects him from the monitored line and return to the tone so that he can ke 


y in 

another 7 digit fone number. When the listener is totally finished with the Remo 
b, he keys 

a single ‘disconnect digit' which disconnects him from the Remob so that the dev 


ice can 
reset and be ready for another caller. 


History of Remobs 


Bell has kept the existence of Remobs very low key. Only in 1974, Bell acknowled 
ged that 
Remobs existed. The device was first made public during hearings on "Telephone M 
onitoring 

Practices by Federal Agencies" before a subcommittee on government operations. H 
ouse of 

Representatives, Ninety-Third Congress, June 1974. It has since been stated by B 
ell that 

the Remob devices are used exclusively for monitoring Bell employees such as ope 
r 

i 

s 


ators, 
nformation operators, etc., to keep tabs on their performance. [Suuureee, were 
tupid] 


Possible Uses for Remobs 


The possible uses of Remobs are almost as endless as the uses of self created f 
one line. 

Imagine the ability to monitor bank lines etc, just off the top of my head I can 
think of 
these applications: 


Data Monitoring of: 


TRW 

National Credit Bureau. 

AT&T Cosmos. 

Bank Institutions. 

CompuServe and other Networks. 


Voice Monitoring of: 


Bank Institutions. 

Mail Order businesses. 

Bell Telephone themselves. 

Any place handling sensitive or important information. 
Anyone that you may not like. 


With just one Remob, someone could get hundreds of credit cards, find out who w 
as on 

vacation, get CompuServe passwords by the dozens, disconnect peoples fones, do c 
redit 
checks, find out about anything that they may want to find out about. I'm sure y 
ou brilliant 

can see the value of a telephone hobbyist and a telecommunications enthusiast ge 
tting his 

hands on a few choice Remobs. <Grin> 


Caution 


If any reader should discover a Remob during his (or her) scanning excursions, p 
lease keep 

in mind the very strict federal laws regarding wiretapping and unauthorized use 
of private 

Bell property. 


102.Scarlet Box Plans by The Jolly Roger 


The purpose of a Scarlet box is to create a very bad connection, it can be used 
to crash a 
BBS or just make life miserable for those you seek to avenge. 


Materials: 


2 alligator clips 

3 inch wire, or a resister (plain wire will create greatest amount of static) (R 
esister will 

decrease the amount of static in proportion to the resister you are using) 


Find the phone box at your victims house, and pop the cover off. 


Find the two prongs that the phone line you wish to box are connected to. 


Hook your alligator clips to your (wire/resister). 


Find the lower middle prong and take off all wires connected to it, I think this 
disables the 

ground and call waiting and shit like that. 

Now take one of the alligator clips and attach it to the upper most prong, and t 
ake the 

other and attach it to the lower middle prong. 


Now put the cover back on the box and take off!! 


xx THTETT PE ** 
xe ot FEE # ** 
THEE EREE / 
E ttt # / 


THEE EREE / 


prongs 


(wire/resister) 


(##)= some phone bullshit 


103.Silver Box Plans by The Jolly Roger 


Introduction: 


First a bit of Phone Trivia. A standard telephone keypad has 12 buttons. These b 
uttons, 

when pushed, produce a combination of two tones. These tones represent the row a 
nd 

column of the button you are pushing. 


851 (7) (8) (9) 
941 (*) (0) (#) 


So (1) produces a tone of 697+1209, (2) produces a tone of 697+1336, etc. 


Function: 


What the Silver Box does is just creates another column of buttons, with the new 
tone of 
1633. These buttons are called A, B, C, and D. 


E 


Usefulness: 


Anyone who knows anything about phreaking should know that in the old days of ph 
reaking, 

phreaks used hardware to have fun instead of other people's Sprint and MCI codes 
. The 

most famous (and useful) was the good ol' Blue Box. However, Ma Bell decided to 

fight back 
and now most phone systems have protections against tone-emitting boxes. This ma 
kes 

boxing just about futile in most areas of the United States (i.e. those areas wi 


th Crossbar 

or Step-By-Step). If you live in or near a good-sized city, then your phone syst 
em is 

probably up-to-date (ESS) and this box (and most others) will be useless. Howeve 
r, if you 

live in the middle of nowhere (no offense intended), you may find a use for this 
and other 

boxes. 


Materials: 


Foot of Blue Wire 

Foot of Gray Wire 

Foot of Brown Wire 
Small SPDT Switch (*) 
Standard Ma Bell Phone 


PrPrPRPH 


(*) SPDT = Single Pole/Double Throw 


Tools: 


1 Soldering Iron 


1 Flat-Tip Screwdriver 


Procedure: 
Loosen the two screws on the bottom of the phone and take the casing off. 
Loosen the screws on the side of the keypad and remove the keypad from the mount 


ing 
bracket. 


Remove the plastic cover from the keypad. 


Turn the keypad so that *0# is facing you. Turn the keypad over. You'll see a bu 
nch of 
wires, contacts, two Black Coils, etc. 


Look at the Coil on the left. It will have five (5) Solder Contacts facing you. 
Solder the Gray 
Wire to the fourth Contact Pole from the left. 


Solder the other end of the Gray Wire to the Left Pole of the SPDT Switch. 


Find the Three (3) Gold-Plated Contacts on the bottom edge of the keypad. On the 
Left 

Contact, gently separate the two touching Connectors (they're soldered together) 
and 

spread them apart. 


Solder the Brown Wire to the Contact farthest from you, and solder the other end 
to the 
Right Pole of the SPDT Switch. 


Solder the Blue Wire to the Closest Contact, and the other end to the Center Pol 
e of the 
SPDT Switch. 


Put the phone back together. 


Using The Silver Box: 


What you have just done was installed a switch that will change the 369# column 
into an 
ABCD column. For example, to dial a 'B', switch to Silver Box Tones and hit '6'. 


No one is sure of the A, B, and C uses. However, in an area with an old phone s 
stem, the 
D' button has an interesting effect. Dial Directory Assistance and hold down 'D 
', The 

phone will ring, and you should get a pulsing tone. If you get a pissed-off oper 
ator, you have 

a newer phone system with defenses against Silver Boxes. At the pulsing tone, di 
a 

T 


she, 


La bot 7. 
hese are loop ends. 


104.Bell Trashing by The Jolly Roger 


The Phone Co. will go to extremes on occasions. In fact, unless you really know 


what to 


expect from them, they will surprise the heck out of you with their "unpublished 
tariffs". 
Recently, a situation was brought to my attention that up till then I had been t 


otally 
unaware 
one co. 


of, least to mention, had any concern about. It involved garbage! The ph 
will 


go as far as to prosecute anyone who rummages through their garbage and helps hi 
mself to 


some 


Of course, they have their reasons for this, and no doubt benefit from such acti 


on. But, 

why should they be so picky about garbage? The answer soon became clear to me: t 

hose 

huge metal bins are filled up with more than waste old food and refuse... Althou 

gh it is 

Pacific Tele. policy to recycle paper waste products, sometimes employees do ove 

rlook this 

sacred operation when sorting the garbage. Thus top-secret confidential Phone Co 
records 

go to the garbage bins instead of the paper shredders. Since it is constantly be 


ing updated 


ith "company memorandums, and supplied with extensive reference material, the P 
one co. 

ust continually dispose of the outdated materials. Some phone companies are sup 
lied each 
ear with the complete "System Practices" guide. This publication is an over 40 
oot long 

ibrary of reference material about everything to do with telephones. As the new 
edition 

arrives each year, the old version of "System Practices" must also be thrown out 


Fis OB ps 


I very quickly figured out where some local phone phreaks were getting their mat 
erial. They 
crawl into the garbage bins and remove selected items that are of particular int 
erest to 
them and their fellow phreaks. One phone phreak in the Los Angeles area has salv 
aged the 
complete 1972 edition of "Bell System Practices". It is so large and was out of 
order (the 
binders had been removed) that it took him over a year to sort it out and create 
enough 
shelving for it in his garage. 


Much of this "Top Secret" information is so secret that most phone companies hav 
e no idea 
what is in their files. They have their hands full simply replacing everything e 
ach time a 
change in wording requires a new revision. It seems they waste more paper than t 
hey can 

read! 


It took quite a while for Hollywood Cal traffic manager to figure out how all of 
the local 
phone phreaks constantly discovered the switchroom test numbers. 


Whenever someone wanted to use the testboard, they found the local phone phreaks 
on the 

lines talking to all points all over the world. It got to the point where the lo 
cal garbage 

buffs knew more about the office operations than the employees themselves. One p 
hreak 

went so far as to call in and tell a switchman what his next daily assignment wo 
uld be. This, 

however, proved to be too much. The switchman traced the call and one phone phre 
ak was 

denied the tool of his trade. 


In another rather humorous incident, a fellow phreak was rummaging through the t 
rash bin 


when h 
silen 
waited 
om the 
lunchr 
ir lo 
Telco 
tioned 
possib 
o the 
heap. 
get th 
police 


1 O 


105.Ca 


800-22 


800-22 


800-26 


800-26 


800-26 


800-26 


e heard someone approaching. He pressed up against the side of the bin and 
tly 
for the goodies to come. You can imagine his surprise when the garbage fr 


oom landed on his head. Most people find evenings best for checking out th 
cal 

trash piles. The only thing necessary is a flashlight and, in the case men 
above, 
ly a rain coat. A word of warning though, before you rush out and dive int 
trash 
It is probably illegal, but no matter where you live, you certainly won't 
e local 

man to hold your flashlight for you. 


nadian WATS Phonebook by The Jolly Roger 


7-4004 ROLM Collagen Corp. 


7-8933 ROLM Collagen Corp. 


8-4500 Voice Mail 
8-4501 ROLM Texaco 
8-4505 Voice Mail 


8-6364 National Data Credit 


800-268-7800 Voice Mai 


800-268-7808 Voice Mai 


800-328-9632 Voice Mail 


800-387-2097 Voice Mail 


800-387-2098 Voice Mail 


800-387-8803 ROLM Canadian Tire 


800-387-8861 ROLM Canadian Tire 


800-387-8862 ROLM Canadian Tire 


800-387-8863 ROLM Canadian Tire 


800-387-8864 ROLM Canadian Tire 


800-387-8870 ROLM Halifax Life 


800-387-8871 ROLM Halifax Life 


800-387-9115 ASPEN Sunsweep 
800-387-9116 ASPEN Sunsweep 
800-387-9175 PBX [Hold Music = CHUM FM] 
800-387-9218 Voice Messenger 
800-387-9644 Carrier 

800-426-2638 Carrier 

800-524-2133 Aspen 


800-663-5000 PBX/Voice Mail [Hold Music = CFMI FM] 


800-663-5996 Voice Mail (5 rings) 


800-847-6181 Voice Mail 


NOTES: Each and every one of these numbers is available to the 604 (British Colu 
TA Most are available Canada Wide and some are located in the United Sta 
ruber’ designated ROLM have been identified as being connected to a ROLM Phonem 
een Numbers designated ASPEN are connected to an ASPEN voice message system. 


Numbers designated VOICE MAIL have not been identified as to equipment in use on 
that 

line. Numbers designated carrier are answered by a modem or data set. Most Voice 
Message 

systems, and ALL Rolms, sound like an answering machine. Press 0 during the reco 


rding when 
in a rolm, * or # or other DTMF in other systems, and be propelled into another 


world. 


106.Hacking TRW by The Jolly Roger 


When you ca 


"TRW". 
RL-G) 
Once T 
g 

with a 
sO AT 


It wi 


Ler 


TRW, the dial up will identify itself with the message 


then wait for you to type the appropriate answer back (such as CT 


his has been done, the system will say "CIRCUIT BUILDING IN PROGRESS" Alon 


few numbers. After this, it clears the screen (CTRL L) followed by a CTRL 


the system sends the CTRL-Q, It is ready for the request. You first type the 4 c 
haracter 


identi 


E 


fier for the geographical area of the account.. 


(For Example) TCA1 - for certain Calif. & Vicinity subscribers. 


TNJ1 - 


TGA1 - 


TCA2 - A second CALF. TRW System. 
Their NJ Database. 


Their Georgia Database. 


The user then types A <CR> and then on the next line, he must type his 3 char. 0 


ption. Most 

Requests use the RTS option. OPX, RTX, and a few others exist. (NOTE) TRW will a 
ccept an 

A, C, or S as the 'X' in the options above.) Then finally, the user types his 7 
digit 

subscriber code. He appends his 3-4 character password after it. It seems that i 
f you 

manage to get hold of a TRW Printout (Trashing at Sears, Saks, ETC. or from gett 
ing your 

credit printout from them) Their subscriber code will be on it leaving only a 3- 


4 character 
p/w up to you. 


For Example, 


(Call the DialUp) 


TRW System Types, (ST) CTRL-G 


(You type, YT) Circuit building in progress 1234 


(ST) CTRL-L CRTL-Q (TCA1 CYT) BTS 3000000AAA 


<CR><CRTL-S> (YT] 


Note: This system is in Half Duplex, Even Parity, 7 Bits per word and 2 Stop Bit 
Ss. 


CAUTION: It is a very stressed rumor that after typing in the TRW password Three 
(3) 

times.. It sets an Automatic Number Identification on your ass, so be careful. A 

nd forget 

who told you how to do this.. 


107.Hacking Vax's & Unix by The Jolly Roger 


Unix is a trademark of AT&T (and you know what that means) 


In this article, we discuss the unix system that runs on the various vax systems 
If you are 

on another unix-type system, some commands may differ, but since it is licensed 

to bell, 


they can't make many changes. 


Hacking onto a unix system is very difficult, and in this case, we advise having 
an inside 
source, if possible. The reason it is difficult to hack a vax is this: Many vax, 
after you get a 

carrier from them, respond=> 


Login: 


They give you no chance to see what the login name format is. Most commonly used 

are 

single words, under 8 digits, usually the person's name. There is a way around t 

his: Most vax 

have an acct. called 'suggest' for people to use to make a suggestion to the sys 

tem root 

terminal. This is usually watched by the system operator, but at late he is prob 

ably at home 

sleeping or screwing someone's brains out. So we can write a program to send at 

the vax 

this type of a message: A screen freeze (Cntl-S), screen clear (system dependant 

), about 

255 garbage characters, and then a command to create a login acct., after which 

you clear 

the screen again, then unfreeze the terminal. What this does: When the terminal 

is frozen, 

it keeps a buffer of what is sent. Well, the buffer is about 127 characters long 
so you 

overflow it with trash, and then you send a command line to create an acct. (Sys 

tem 

dependant). After this you clear the buffer and screen again, then unfreeze the 

terminal. 


This is a bad way to do it, and it is much nicer if you just send a command to t 
he terminal to 

shut the system down, or whatever you are after... There is always, *Always* an 

acct. called 

root, the most powerful acct. to be on, since it has all of the system files on 

it. If you hack 

your way onto this one, then everything is easy from here on... On the unix syst 
em, the 

abort key is the Cntl-D key. Watch how many times you hit this, since it is also 


a way to log 
off the system! A little about unix architecture: The root directory, called roo 
t, is where 
the system resides. After this come a few 'sub' root directories, usually to gro 


up things 

(stats here, priv stuff here, the user log here...). Under this comes the superu 
ser (the 

operator of the system), and then finally the normal users. In the unix 'Shell' 


everything is 
treated the same. 


By this we mean: You can access a program the same way you access a user directo 
ry, and so 

on. The way the unix system was written, everything, users included, are just pr 
ograms 
belonging to the root directory. Those of you who hacked onto the root, smile, s 
ince you can 

screw everything...the main level (exec level) prompt on the unix system is the 
$, and if you 

are on the root, you have a # (superuser prompt). Ok, a few basics for the syste 
m... To see 

where you are, and what paths are active in regards to your user account, then t 


ype 


=> pwd 


This shows your acct. separated by a slash with another pathname (acct.), possib 
ly many 
times. To connect through to another path, or many paths, you would type: 


You=> pathl/path2/path3 


And then you are connected all the way from pathl to path3. You can 
run the programs on all the paths you are connected to. If it does 
not allow you to connect to a path, then you have insufficient privs, or 


the path is closed and archived onto tape. You can run programs this way 


also: 


you=> pathl/path2/path3/program-name 


Unix treats everything as a program, and thus there a few commands to learn... 


To see what you have access to in the end path, type: 


ls 


for list. This show the programs you can run. You can connect to the root direct 
ory and run 
it's programs with=> 


/root 


By the way, most unix systems have their log file on the root, so you can set up 
a watch on 

the file, waiting for people to log in and snatch their password as it passes th 
ru the file. To 
connect to a directory, use the command: 


=> cd pathname 


This allows you to do what you want with that directory. You may be asked for a 
password, 

but this is a good way of finding other user names to hack onto. The wildcard ch 
aracter in 

unix, if you want to search down a path for a game or such, is the *. 


=> ls /* 


Should show you what you can access. The file types are the same as they are on 
a dec, so 
refer to that section when examining file. To see what is in a file, use the 


=> pr 


filename command, for print file. We advise playing with pathnames to get the ha 
ng of the 

concept. There is on-line help available on most systems with a 'help' or a '?'. 
We advise 
you look thru the help files and pay attention to anything they give you on path 
names, or the 

commands for the system. You can, as a user, create or destroy directories on th 
e tree 

beneath you. This means that root can kill everything but root, and you can kill 
any that are 

below you. These are the 


=> mkdir pathname 


=> rmdir pathname 


commands. Once again, you are not alone on the system... type=> 


who 


to see what other users are logged in to the system at the time. If you 


want to talk to them=> 


write username 


Wi allow you to chat at the same time, without having to worry about the parse 
r. To send 
mail to a user, say 


=> mail 


And enter the mail sub-system. To send a message to all the users on the system, 
say 


=> wall 


Which stands for ‘write all'. By the way, on a few systems, all you have to do i 
s hit the 

<return> key to end the message, but on others you must hit the cntl-D key. To s 
end a single 

message to a user, say 


=> write username 


this is very handy again! If you send the sequence of characters discussed at th 
e very 

beginning of this article, you can have the super-user terminal do tricks for yo 
u again. 


Privs: 


If you want superuser privs, you can either log in as root, or edit your acct. s 
o it can say 


=> su 


this now gives you the # prompt, and allows you to completely by-pass the protec 
tion. The 

wonderful security conscious developers at bell made it very difficult to do muc 
h without 

privs, but once you have them, there is absolutely nothing stopping you from doi 
ng anything 

you want to. To bring down a unix system: 


=> chdir /bin 


=> rm * 


this wipes out the pathname bin, where all the system maintenance files are. Or 
try: 


=> P AF 


This recursively removes everything from the system except the remove command it 
self. 
Or try: 


=> kill -1,1 


=> sync 


This wipes out the system devices from operation. When you are finally sick and 
tired from 
hacking on the vax systems, just hit your cntl-d and repeat key, and you will ev 
entually be 
logged out. 


The reason this file seems to be very sketchy is the fact that bell has 7 licens 
ed versions 
of unix out in the public domain, and these commands are those common to all of 
them. I 

recommend you hack onto the root or bin directory, since they have the highest 1 
evels of 

privs, and there is really not much you can do (except develop software) without 
them. 


108.Verification Circuits by The Jolly Roger 


One busy verification conference circuit is always provided. The circuit is a th 
ree-way 
conference bridge that enables an operator to verify the busy/idle condition of 
a 

subscriber line. Upon request of a party attempting to reach a specified directo 
ry 

number, the operator dials the called line number to determine if the line is in 
use, if 
the receiver is off the hook, or if the line is in lockout due to a fault condit 
ion. The 

operator then returns to the party trying to reach the directory number and stat 
es the 


condition of the line. Lines with data security can not be accessed for busy ver 


ification 


when the line is in use. (Refer also to data security.) 


Three ports are assigned to each busy verification conference circuit. One port 


is for 


operator access and two ports are used to split an existing connection. To verif 


y the 


busy/idle condition of a line, the operator established a connection to the oper 


ator 

access port and dials the 
ne is in 

use, the existing connect 
e other 

two ports of the busy ver 
on circuit 


directory number of the line to be verified. If the li 


ion is broken and immediately re-established through th 


ification circuit without interruption. Busy verificati 


is controlled by access code. A dedicated trunk can be used but is not necessary 


The busy verification circuit also can be used for test verify from the wire chi 


efs test 


ight out 
of an ESS manual word for 
Not 


panel B. Additional busy verification conference circuits (002749) there it is r 


word! And I'm getting 25 linear feet of ESS manuals!!! 


counting the stack received so far! 


109.White Box Plans by The Jolly Roger 


Introduction: 
The White Box is simply a 


uch-tone, 
see my Silver Box Plans. 


Materials: 


1 Touch-Tone Keypad 


2 9V Batteries 
2 9V Battery Clips 


Procedure: 


portable touch-tone keypad. For more information on to 


1 Miniature 1000 to 8 Ohm Transformer (Radio Shack # 273-1380) 
1 Standard 8 Ohm Speaker 


Connect the Red Wire from the Transformer to either terminal on the speaker. 


Connect the White Wire from the transformer to the other terminal on the speaker 


Connect the Red Wire from one Battery Clip to the Black Wire from the other Batt 


Connect the Red Wire from the second Battery Clip to the Green Wire from the Key 


Connect the Blue Wire from the Keypad to the Orange/Black Wire from the Keypad. 


Connect the Black Wire from the first Battery Clip to the two above wires (Blue 
and 
Black/Orange). 


Connect the Black Wire from the Keypad to the Blue Wire from the Transformer. 


Connect the Red/Green Wire from the Keypad to the Green Wire from the Transforme 
ie 


Make sure the Black Wire from the Transformer and the remaining wires from the K 
eypad 
are free. 


Hook up the Batteries. 


Optional: 


Put it all in a case. 


Add a Silver Box to it. 


Use: 


Just use it like a normal keypad, except put the speaker next to the receiver of 
the phone 
you're using. 


110.The BLAST Box by The Jolly Roger 


Ever want to really make yourself be heard? Ever talk to someone on the phone wh 


o just 

doesn't shut up? Or just call the operator and pop her eardrum? Well, up until r 
ecently it 

has been impossible for you to do these things. That is, unless of course you've 
got a blast 


box. All a blast box is, is a really cheap amplifier, (around 5 watts or so) con 

nected in place 

of the microphone on your telephone. It works best on model 500 AT&T Phones, and 
if 

constructed small enough, can be placed inside the phone. 


Construction: 


Construction is not really important. Well it is, but since I'm letting you make 


your own amp, I really don't have to include this. 


Usage: 


Once you've built your blast box, simply connect a microphone (or use the microp 
hone from 
the phone) to the input of the amplifier, and presto. There it is. Now, believe 
it or not, this 

device actually works. (At least on crossbar.) It seems that Illinois bell switc 
hing systems 

allow quite a lot of current to pass right through the switching office, and out 
to whoever 

you're calling. When 


you talk in the phone, it comes out of the other phone (again it works best if t 
he phone that 

you're calling has the standard western electric earpiece) incredibly loud. This 
device is 

especially good for PBS Subscription drives. Have "Phun", and don't get caught! 


111.Dealing with the Rate & Route Operator by The Jolly Roger 


It seems that fewer and fewer people have blue boxes these days, and that is rea 
lly too 

bad. Blue boxes, while not all that great for making free calls (since the TPC c 
an tell when 
the call was made, as well as where it was too and from), are really a lot of fu 
n to play with. 
Short of becoming a real live TSPS operator, they are about the only way you can 

really play 
with the network. 


For the few of you with blue boxes, here are some phrases which may make life ea 
sier when 

dealing with the rate & route (R&R) operators. To get the R&R op, you send a KP 

+ 141 + ST. 

In some areas you may need to put another NPA before the 141 (i.e., KP + 213 + 1 
4] + ST), if 

you have no local R&R ops. 


The R&R operator has a myriad of information, and all it takes to get this data 
is mumbling 
cryptic phrases. There are basically four special phrases to give the R&R ops. T 
hey are 

NUMBERS route, DIRECTORY route, OPERATOR route, and PLACE NAME. 


To get an R&R an area code for a city, one can call the R&R operator and ask for 
the 

numbers route. For example, to find the area code for Carson City, Nevada, we'd 
ask the 

R&R op for "Carson City, Nevada, numbers route, please." and get the answer, "Ri 
ght... 702 

plus." meaning that 702 plus 7 digits gets us there. 


Sometimes directory assistance isn't just NPA+131. The way to get these routings 
is to call 

R&R and ask for "Anaheim, California, directory route, please." Of course, she'd 
tell us it 

was 714 plus, which means 714 + 131 gets us the D.A. op there. This is sort of p 
ointless 

example, but I couldn't come up with a better one on short notice. 


Let's say you wanted to find out how to get to the inward operator for Sacrement 
O; 

California. The first six digits of a number in that city will be required (the 
NPA and an 

NXX). For example, let us use 916 756. We would call R&R, and when the operator 
answered, say, "916 756, operator route, please." The 


operator would say, "916 plus 001 plus." This means that 916 + 001 + 121 will ge 
t you the 

inward operator for Sacramento. Do you know the city which corresponds to 503 64 
0? The 

R&R operator does, and will tell you that it is Hillsboro, Oregon, if you sweetl 
y ask for 

"Place name, 503 640, please." 


For example, let's say you need the directory route for Sveg, Sweden. Simply cal 
1 R&R, and 
ask for, "International, Baden, Switzerland. TSPS directory route, please." In r 
esponse to 
this, you'd get, "Right... Directory to Sveg, Sweden. Country code 46 plus 1170. 
" So you'd 
route yourself to an international sender, and send 46 + 1170 to get the D.A. op 
erator in 
Sweden. 


Inward operator routings to various countries are obtained the same way "Interna 
tional, 


London, England, TSPS inward route, please." and get "Country code 44 plus 121." 
Therefore, 
44 plus 121 gets you inward for London. 


Inwards can get you language assistance if you don't speak the language. Tell th 
e foreign 

inward, “United States calling. Language assistance in completing a call to (cal 
led party) at 

(called number) ." 


R&R operators are people are people too, y'know. So always be polite, make sure 
use of ‘em, 
and dial with care. 


112.Cellular Phreaking by The Jolly Roger 


The cellular/mobile phone system is one that is perfectly set up to be exploited 

by phreaks 
with the proper knowledge and equipment. Thanks to deregulation, the regional BO 
C's (Bell 
Operating Companies) are scattered and do not communicate much with each other. 
Phreaks 


can take advantage of this by pretending to be mobile phone customers whose "hom 
e base" 

is a city served by a different BOC, known as a "roamer". Since it is impractica 
L for each 

BOC to keep track of the customers of all the other BOC's, they will usually all 
ow the 

customer to make the calls he wishes, often with a surcharge of some sort. 


The bill is then forwarded to the roamer's home BOC for collection. However, it 
is fairly 
simple (with the correct tools) to create a bogus ID number for your mobile phon 
e, and 

pretend to be a roamer from some other city and state, that's "just visiting". W 
hen your 
BOC tries to collect for the calls from your alleged "home BOC", they will disco 
ver you are 
not a real customer; but by then, you can create an entirely new electronic iden 
tity, and use 

that instead. 


How does the cellular system know who is calling, and where they are? When a mob 
ile phone 
enters a cell's area of transmission, it transmits its phone number and its 8 di 
git ID number 
to that cell, who will keep track of it until it gets far enough away that the s 
ound quality is 
sufficiently diminished, and then the phone is "handed off" to the cell that the 
customer 
has walked or driven into. This process continues as long as the phone has power 
and is 

turned on. If the phone is turned off (or the car is), someone attempting to cal 
l the mobile 

phone will receive a recording along the lines of "The mobile phone customer you 
have dialed 

has left the vehicle or driven out of the service area." When a call is made to 
a mobile 

phone, the switching equipment will check to see if the mobile phone being calle 
d 

i 

c 

p 

y 

t 


is "logged 
n", so to speak, or present in one of the cells. If it is, the call will then a 
t (to the speaking 

arties) just like a normal call - the caller may hear a busy tone, the phone ma 
just ring, or 

he call may be answered. 


How does the switching equipment know whether or not a particular phone is autho 
rized to 
use the network? Many times, it doesn't. When a dealer installs a mobile phone, 
he gives the 
phone's ID number (an 8 digit hexadecimal number) to the local BOC, as well as t 
he phone 
number the BOC assigned to the customer. Thereafter, whenever a phone is present 
in one 
of the cells, the two numbers are checked - they should be registered to the sam 


e person. 

If they don't match, the telco knows that an attempted fraud is taking place (or 
at best, 

some transmission error) and will not allow calls to be placed or received at th 
at phone. 
However, it is impractical (especially given the present state of deregulation) 
for the telco 

to have records of every cellular customer of every BOC. Therefore, if you're go 
ing to 

create a fake ID/phone number combination, it will need to be "based" in an area 
that has a 

cellular system (obviously), has a different BOC than your local area does, and 

has some 

sort of a "roamer" 


agreement with your local BOC. 


How can one "phreak" a cellular phone? There are three general areas when phreak 
ing 

cellular phones; using one you found in an unlocked car (or an unattended walk-a 
bout model), 

modifying your own chip set to look like a different phone, or recording the pho 
ne 
number/ID number combinations sent by other local cellular phones, and using tho 
se as your 

own. Most cellular phones include a crude "password" system to keep unauthorized 
users 

from using the phone - however, dealers often set the password (usually a 3 to 5 
digit code) 

to the last four digits of the customer's mobile phone number. If you can find t 
hat 


somewhere on the phone, you're in luck. If not, it shouldn't be TOO hard to hack 
, since 

most people aren't smart enough to use something besides "1111", "1234", or what 
ever. If 

you want to modify the chip set in a cellular phone you bought (or stole), there 
are two chips 

(of course, this depends on the model and 


manufacturer, yours may be different) that will need to be changed - one install 
ed at the 

manufacturer (often epoxied in) with the phone's ID number, and one installed by 
the 

dealer with the phone number, and possible the security code. To do this, you'll 
obviously 
need an EPROM burner as well as the same sort of chips used in the phone (or a f 
riendly and 


unscrupulous dealer!). As to recording the numbers of other mobile phone custome 
rs and 
using them; as far as I know, this is just theory... but it seems quite possible 


, if you've got 
the equipment to record and decode it. The cellular system would probably freak 
out if two 
phones (with valid ID/phone number combinations) were both present in the networ 
k at 
once, but it remains to be seen what will happen. 


113.Cheesebox Plans by The Jolly Roger 


A Cheesebox (named for the type of box the first one was found in) is a type of 
box which 

will, in effect, make your telephone a Pay-Phone..... This is a simple, modernize 
d, and easy way 

of doing it.... 


Inside Info: These were first used by bookies many years ago as a way of making 
calls to 
people without being called by the cops or having their numbers traced and/or ta 


How To Make A Modern Cheese Box 


Ingredients: 


1 Call Forwarding service on the line 
1 Set of Red Box Tones 
The number to your prefix's Intercept operator (do some scanning for this one) 


How To: 


After you find the number to the intercept operator in your prefix, use your cal 
]- 
forwarding and forward all calls to her...this will make your phone stay off the 


hook (actually, now it waits for a quarter to be dropped in)...you now have a che 
ese box... In 
Order To Call Out On This Line: You must use your Red Box tones and generate the 


quarter 

dropping in...then, you can make phone calls to people...as far as I know, this 
is fairly safe, 

and they do not check much...Although I am not sure, I think you can even make c 
redit-card 


calls from a cheesebox phone and not get traced... 


114.How to start your own conferences! by The Jolly Roger 


Black Bart showed how to start a conference call thru an 800 exchange, and I wil 
1 now 

explain how to start a conference call in a more orthodox fashion, the 2600Hz. 
one. 


Firstly, the fone company has what is called switching systems. There are severa 
l types, but 
the one we will concern ourselves with, is ESS (electronic switching system). If 
your area is 
zoned for ESS, do not start a conference call via the 2600Hz. Tone, or bell secu 


rity will nai 
your ass! To find out if you are under ESS, call your local business office, and 
ask them if 


you can get call waiting/forwarding, and if you can, that means that you are in 
ESS country, 

and conference calling is very, very dangerous!!! Now, if you are not in ESS, yo 
u will need the 

following equipment: 


An Apple CAT II modem 
A copy of TSPS 2 or CAT'S Meow 
A touch tone fone line 
A touch tone fone. (True tone) 


Now, with TSPS 2, do the following: 


Run tsps 2 


Chose option 1 


Chose option 6 


Chose sub-option 9 


Now type: 1-514-555-1212 (dashes are not needed) 


Listen with your handset, and as soon as you hear a loud click, then type: $ 


To generate the 2600 hz. Tone. This obnoxious tone will continue for a few 
Seconds, then listen again and you should hear another loud 'click'. 


Now type: km2130801050s 


'K' = kp tone 
'M' = multi frequency mode 
'S' = s tone 


Now listen to the handset again, and wait until you hear the 'click' again. Then 
type: 
km2139752975s 


2139751975 is the number to bill the conference call to. 


Note: 213-975-1975 is a disconnected number, and I strongly advise that you only 
bill the 

call to this number, or the fone company will find out, and then.. remember, con 
ference calls 

are itemized, so if you do bill it to an enemy's number, he can easily find out 
who did it and 

he can bust you! 


You should now hear 3 beeps, and a short pre-recorded message. From here on, eve 
rything 
is all menu driven. 


Conference call commands 


From the '#' mode: 


= ca a number 

= transfer control 

hangs up the conference call 

= wi call a conference operator 


Ouo 
Il 


Stay away from 7 and 9! If for some reason an operator gets on-line, hang up! If 
you get a 

busy signal after km2130801050s, that means that the teleconference line is temp 
orarily 
down. Try later, preferably from 9am to 5pm week days, since conference calls ar 
e primarily 

designed for business people. 


115.Gold Box Plans by The Jolly Roger 


HOW TO BUILD IT 


You will need the following: 


Two 10K OHM and three 1.4K OHM resistors 

Two 2N3904 transistors 

Two Photo Cells 

Two Red LED'S (The more light produced the better) 
A box that will not let light in 

Red and Green Wire 


Light from the #1 LED must shine directly on the photocell #1. The gold box I ma 
de needed 
the top of the LED's to touch the photo cell for it to work. 


The same applies to the #2 photo cell and LED. 


1 


:-PHOTOCELL--: 


: BASE 


| TTTTT 


+LED- TRANSISTOR 


TELEF 


-I(-- : :COLLECTOR 


RED1--< >:--: : : GREEN2 


Z EEEIEE AFLEI Se a de a a 


LED 10K 10K 1.4K 1.4K 


RESISTORES 


2 


-PHOTOCELL 


BASE : 


EET Es 


TRANSISTOR : 


TILEF; 


:EMITTER : 


GREEN1 RED2 


/+/+/ 


The 1.4K resistor is variable and if the second part of the gold box is skipped 
it will stil 
work but when someone picks up the phone they will hear a faint dial tone in the 
background 

and might report it to the Gestapo er... (AT&T). 1.4K will give you good receptio 
n with little 

risk of a Gestapo agent at your door. 


Now that you have built it take two green wires of the same length and strip the 
ends, twist 
two ends together and connect them to greenl and place a piece of tape on it wit 

h "line #1" 

writing on it. 


Continue the process with redl only use red wire. Repeat with red2 and green2 bu 
t change 
to line #2. 


HOW TO INSTALL 


You wi need to find two phone lines that are close together. Label one of the 

phone lines 

"Line #1". Cut the phone lines and take the outer coating off it. There should b 
e 4 wires. 

Cut the yellow and black wires off and strip the red and green wires for both li 
nes. 


Line #1 should be in two pieces. Take the green wire of one end and connect it t 
o one of the 

green wires on the gold box. Take the other half of line #1 and hook the free gr 
een wire to 

the green wire on the phone line. Repeat the process with redl and the other lin 
e. All you 

need to do now is to write down the phone numbers of the place you hooked it up 
at and go 

home and call it. You should get a dial tone!!! If not, try changing the emitter 
with the 

collector. 


116.The History of ESS by The Jolly Roger 


Of all the new 1960s wonders of telephone technology - satellites, ultra modern 
Traffic 

Service Positions (TSPS) for operators, the picturephone, and so on - the one th 
at gave Be 
Labs the most trouble, and unexpectedly became the greatest development effort i 
n Bell 
System's history, was the perfection of an electronic switching system, or ESS. 


It may be recalled that such a system was the specific end in view when the proj 
ect that 

had culminated in the invention of the transistor had been launched back in the 

1930s. 

After successful accomplishment of that planned miracle in 1947-48, further dela 
ys were 
brought about by financial stringency and the need for further development of th 
e 

transistor itself. In the early 1950s, a Labs team began serious work on electro 
nic 

switching. As early as 1955, Western Electric became involved when five engineer 
s from the 
Hawthorne works were assigned to collaborate with the Labs on the project. The p 
resident 
of AT&T in 1956, wrote confidently, "At Bell Labs, development of the new electr 
onic 
switching system is going full speed ahead. We are sure this will lead to many i 
mprovements 


in service and also to greater efficiency. The first service trial will start in 
Morris, Ill., in 
1959." Shortly thereafter, Kappel said that the cost of the whole project would 
probably be 
$45 million. 


But it gradually became apparent that the development of a commercially usable e 
lectronic 
switching system - in effect, a computerized telephone exchange - presented vast 
ly greater 
technical problems than had been anticipated, and that, accordingly, Bell Labs h 
ad vastly 
underestimated both the time and the investment needed to do the job. The year 1 
959 
passed without the promised first trial at Morris, Illinois; it was finally made 
in November 
1960, and quickly showed how much more work remained to be done. As time dragged 
on and 
costs mounted, there was a concern at AT&T and something approaching panic at Be 
11 Labs. 
But the project had to go forward; by this time the investment was too great to 
be 
sacrificed, and in any case, forward projections of increased demand for telepho 
ne service 
indicated that within a few years a time would come when, without the quantum le 
ap in 
speed and flexibility that electronic switching would provide, the national netw 
ork would be 
unable to meet the demand. In November 1963, an all-electronic switching system 
went into 
use at the Brown Engineering Company at Cocoa Beach, Florida. But this was a sma 
1l 
installation, essentially another test installation, serving only a single compa 
ny. Kappel's tone 
on the subject in the 1964 annual report was, for him, an almost apologetic: "El 
ectronic 
switching equipment must be manufactured in volume to unprecedented standards of 


reliability.... To turn out the equipment economically and with good speed, mass 
production 

methods must be developed; but, at the same time, there can be no loss of precis 
iOler” 
Another year and millions of dollars later, on May 30, 1965, the first commercia 
L electric 
central office was put into service at Succasunna, New Jersey. 


Even at Succasunna, only 200 of the town's 4,300 subscribers initially had the b 
enefit of 

electronic switching's added speed and additional services, such as provision fo 
r three 

party conversations and automatic transfer of 
S was on its 
way. In January 1966, the second commercial installation, this one serving 2,900 
telephones, 

went into service in Chase, Maryland. By the end of 1967 there were additional E 


incoming calls. But after that, ES 


SS offices 

in California, Connecticut, Minnesota, Georgia, NY, Florida, and Pennsylvania; b 
y the end of 
1970 there were 120 offices serving 1.8 million customers; and by 1974 there wer 
e 475 
offices serving 5.6 million customers. 


The difference between conventional switching and electronic switching is the di 
fference 

between "hardware" and "software"; in the former case, maintenance is done on th 
€ spot, 

with screwdriver and pliers, while in the case of electronic switching, it can b 
e done 

remotely, by computer, from a central point, making it possible to have only one 
or two 

technicians on duty at a time at each switching center. The development program, 
when the 

final figures were added up, was found to have required a staggering four thousa 
nd man- 

years of work at Bell Labs and to have cost not $45 million but $500 million! 


117.The Lunch Box by The Jolly Roger 


Introduction 


The Lunch Box is a VERY simple transmitter which can be handy for all sorts of t 
hings. It is 

quite small and can easily be put in a number of places. I have successfully use 
d it for 

tapping fones, getting inside info, blackmail and other such things. The possibi 
ities are 

endless. I will also include the plans or an equally small receiver for your new 
ly made toy. 


Use it for just about anything. You can also make the transmitter and receiver t 
ogether in 
one box and use it as a walkie talkie. 
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Materials you will need 


9 volt battery with battery clip 


-mfd, 15 volt electrolytic capacitor 
047 mfd capacitors 

22 mfd capacitor 

pf capacitor 

5 pf variable capacitor 

ansistor antenna coil 


2N464 transistor 


Ok resistor 
6k resistor 
k resistor 


2meg potentiometer with SPST switch 
ome good wire, solder, soldering iron, board to put it on, box (optional) 


Schematic for The Lunch Box 


This may get a tad confusing but just print it out and pay attention. 


base collector 


! )( 2N366 4 /\/\/ GND 


365 pf () emitter ! 


GND / .022mfd ! ! 


TOKN Ak 


/ GND + emitter 
! ' ! 2N464 


/ .0047 ! base collector 


2meg \ r !o! 4 + | 
/ ! GND! ! ! 


GND ! ! ! 


microphone +--/\/\/ 


GND >/< I4l4l4 
switch Battery 


from 2meg pot. 


Notes about the schematic 
GND means ground 


The GND near the switch and the GND by the 2meg potentiometer should be connecte 
d. 


Where you see: ) ( 


() 


)( it is the transistor antenna coil with 15 turns of regular hook-up wire arou 
nd it. 


The middle of the loop on the left side (the left of "()") you should run a wire 
down to the 

"+" which has nothing attached to it. There is a .0047 capacitor on the correct 

piece of 

wire. 


For the microphone use a magnetic earphone (1k to 2k). 


Where you see "[!]" is the antenna. Use about 8 feet of wire to broadcast approx 
300ft. 

Part 15 of the FCC rules and regulation says you can't broadcast over 300 feet w 

ithout 

a license. (Hahaha). Use more wire for an antenna for longer distances. (Attach 

it to the 

black wire on the fone line for about a 250 foot antenna!) 


Operation of the Lunch Box 


This transmitter will send the signals over the AM radio band. You use the varia 
ble 

capacitor to adjust what freq. you want to use. Find a good unused freq. down at 
the lower 

end of the scale and you're set. Use the 2 meg pot. to adjust gain. Just fuck wi 
th it until 

you get what sounds good. The switch on the 2meg is for turning the Lunch Box on 


£ 


and off. 
When everything is adjusted, turn on an AM radio adjust it to where you think th 
e signal is. 
Have a friend lay some shit thru the Box and tune in to it. That's all there is 
to it. The plans 

for a simple receiver are shown below: 


The Lunch Box receiver 


9 volt battery with battery clip 
365 pf variable capacitor 

51 pf capacitor 

1N38B diode 
Transistor antenna coil 
2N366 transistor 

SPST toggle switch 

1k to 2k magnetic earphone 


ee ee ee ee Ee ee 
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Schematic for receiver 
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GND >/< } 


switch 


Closing statement 


This two devices can be built for under a total of $10.00. Not too bad. Using th 
ese devices 
in illegal ways is your option. If you get caught, I accept NO responsibility fo 
r your actions. 

This can be a lot of fun if used correctly. Hook it up to the red wire on the ph 
one line and it 

will send the conversation over the air waves. 


118.0live Box Plans by The Jolly Roger 


This is a relatively new box, and all it basically does is serve as a phone rin 
ger. You have 

two choices for ringers, a piezoelectric transducer (ringer), or a standard 8 oh 
m speaker. 

The speaker has a more pleasant tone to it, but either will do fine. This circui 
t can also be 
used in conjunction with a rust box to control an external something or other wh 
en the 
phone rings. Just connect the 8 ohm speaker output to the inputs on the rust box 
, and 

control the pot to tune it to light the light (which can be replaced by a relay 
for external 

controlling) when the phone rings. 
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c. Electromagnetic transducer 


Parts List 


Ul - Texas Instruments TCM1506 
T1 - 4000:8 ohm audio transformer 
S1 - 8 ohm speaker 


Rl - 2.2k resistor 

R2 - External variable resistor; adjusts timing frequency 
Cl - .47uF capacitor 

C2 - .luF capacitor 

C3 - 10uF capacitor 

Ll = Tip 

L2 - Ring 

L1 and L2 are the phone line. 


Shift Rate: 


This is the formula for determining the shift rate: 


SR = = = 67 Hz 


(DSR(1/£1)+DSR(1/f2)) 128 128 


——= aai + ——— 


1714 1500 


fl 


Ul 


£2 


DSR = Shift Devider Rate ratio = 128 
High Output Frequency = 1714 
Low Output Frequency = 1500 


119.The Tron Box by The GREAT Captain Crunch!! 


(C)=capacitor 
F =fuse 
R =resistor 
I,- are wire 


Parts List: 


) 
) 
) 120Volt fuse 
n less 


(1) electrically 


it keeps you from blowing your breaker just in case...) 
(1) power cord (cut up an extension cord. Need plug part and wire) 


electrolytic capacitors rated at 50V(lowest) .47UF 
20-30 OHM « Watt resistor 


(amp rating best to use at least half of total house current or 


insulated box for the rest of us. If your don't feel comfortabl 


e about 


electricity then don't play with this. There is voltage present that will ***kil 
1 you***, 


The thing works when the load in your house is low like at night time. It will p 

ut a reverse 

phase signal on the line and cancel out the other phase and put a reverse phase 

running 

everything in the house. Well if you have ever switched the power leads on a D\C 
(battery 

powered) motor you will see that it runs backwards well your electric meter sort 
of works 

this way...so reverse phase makes the meter slow down and if your lucky it will 

go 

backwards. Anyway it means a cheaper electric bill. 


120.More TRW Info by The Jolly Roger 


TRW is a large database in which company's and banks can run credit checks on th 
eir 

customers. Example: John Jones orders $500 worth of stereo equipment from the Jo 
e Blow 


Electronic distributing Co. Well it could be that he gave the company a phony cr 
edit card 

number, or doesn't have enough credit, etc. Well they call up TRW and then run a 
check on 

him, TRW then lists his card numbers (everything from sears to visa) and tells t 
he numbers, 

credit, when he lost it last (if he ever did) and then of course tells if he has 
had any prior 

problems paying his bills. 


I would also like to add that although TRW contains information on millions of p 
eople, not 
every part of the country is served, although the major area are.. So if you hat 
e someone 

and live in a small state, you probably wont be able to order him 300 pink toile 
t seats from 

K-mart. 


Logging on 


To log on, you dial-up your local access number (or long-distance, what ever tur 
ns you on) 

and wait for it to say "IRW" at this prompt, you type either an "A" or a "Ctrl-G 
"and it will 
say "circuit building in progress" it will wait for a minute and then clear the 
screen, now you 

will type one of the following. 


Tcal 
Tca2 


TAJL 


Tgal 


This is to tell it what geographical area the customer is in, it really doesn't 
matter which 
you use, because TRW will automatically switch when it finds the record.. 


Next, you will type in the pswd and info on the person you are trying to get cre 
dit info on. 
You type it in a format like this: 


Rts Pswd Lname Fname ...,House number First letter of street name Zip <cr> now y 
ou type 
ctrl s and 2 ctrl-Q's here is what it looks like in real life: 


Ae: Dialing XXX-XXX-XXXX 


(screen clear) 


TRW ^G 


circuit building in progress 


(pause . . . screen clear) 


Tcal 


Rtc 3966785-cm5 Johnson David 


R 56785 


26+, 4567 


and then it will wait for a few seconds and print out the file on him (if it can 
locate one for 
the guy) 


Note: You may have to push return when you first connect to get the systems atte 
ntion. 


Getting Your Passwords 


To obtain pswds, you go down to your favorite bank or sears store and dig throug 
h the trash 
(hence the name trashing) looking for printouts, if they are a big enough place, 
and live ina 

TRW area, then they will probably have some. The printouts will have the 7 digit 
subscriber 
code, leaving the 3-4 digit pswd up to you. Much like trashing down at good old 

ma bell. 


121.Phreaker's Phunhouse by the Jolly Roger 


The long awaited pregquil to Phreaker's Guide has finally arrived. Conceived from 
the 

boredom and loneliness that could only be derived from: The Traveler! But now, h 
e has 

returned in full strength (after a small vacation) and is here to 'World Premier 
e' the new 
files everywhere. Stay cool. This is the preguil to the first one, so just relax 
. This is not 
made to be an exclusive ultra elite file, so kinda calm down and watch in the ba 
ckground if 

you are too cool for it. 


Phreak Dictionary 


Here you will find some of the basic but necessary terms that should be known by 
any 
phreak who wants to be respected at all. 


Phreak: 


The action of using mischievous and mostly illegal ways in order to not pay for 
some 
sort of telecommunications bill, order, transfer, or other service. It often 


involves usage of highly illegal boxes and machines in order to defeat the 
security that is set up to avoid this sort of happening. [fr'eaking]. v. 


A person who uses the above methods of destruction and chaos in order to make a 
better life for all. A true phreaker will not go against his fellows or narc on 
people who have ragged on him or do anything termed to be dishonorable to 
phreaks. [fr'eek]. n. 


A certain code or dialup useful in the action of being a phreak. (Example: "I ha 
cked 
a new metro phreak last night.") 


Switching System: 


There are 3 main switching systems currently employed in the US, and a few other 


systems will be mentioned as background. 


SxS: This system was invented in 1918 and was employed in over half of 
the country until 1978. It is a very basic system that is a general waste 
of energy and hard work on the linesman. A good way to identify this is 

that it requires a coin in the phone booth before it will give you a dial 
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The use of personally designed boxes that emit or cancel electronical impulses t 


h 


at 


allow simpler acting while phreaking. Through the use of separate boxes, you can 


accomplish most feats possible with or without the control of an operator. 


Some boxes and their functions are listed below. Ones marked with 


at 


they are not operatable in ESS. 


"x! indicate t 


*Black Box:Makes it seem to the phone company that the phone was 


ever picked up. 


Blue Box: Emits a 2600hz tone that allows you to do such things as stack 
a trunk line, kick the operator off line, and others. 

Red Box: Simulates the noise of a quarter, nickel, or dime being dropped 
into a payphone. 
Cheese Box: Turns your home phone into a pay phone to throw off traces 
(a red box is usually needed in order to call out.) 

[| *Clear Box: Gives you a dial tone on some of the old SxS payphones 
without putting in a coin. 
Beige Box: A simpler produced linesman's handset that allows you to tap 
into phone lines and extract by eavesdropping, or crossing wires, etc. 
Purple Box: Makes all calls made out from your house seem to be local 
calls. 


ANI [ANI]: 


Automatic Number Identification. A service available on ESS that allows a phone 
service [see Dialups below] to record the number that any certain code was 
dialed from along with the number that was called and print both of these on 
the customer bil 


dialups [see Dialups below] are all designed just to use ANI. Some of the servic 
es do 
not have the proper equipment to read the ANI impulses yet, but it is impossible 


to see which is which without being busted or not busted first. 


Dialups [dy'l'ups]: 


Any local or 800 extended outlet that allows instant access to any service such 
as 
MCI, Sprint, or AT&T that from there can be used by hand-picking or using a 
program to reveal other peoples codes which can then be used moderately until 
they find out about it and you must switch to another code (preferably before 
they find out about it.) 


Dialups are extremely common on both senses. Some dialups reveal the company tha 
t 
operates them as soon as you hear the tone. Others are much harder and some 
you may never be able to identify. A small list of dialups: 


1-800-421-9438 (5 digit codes) 


1-800-547-6754 (6 digit codes) 


1-800-345-0008 (6 digit codes) 


1-800-734-3478 (6 digit codes) 


1-800-222-2255 (5 digit codes) 


Codes: Codes are very easily accessed procedures when you call a dialup. They wi 


give you some sort of tone. If the tone does not end in 3 seconds, then punch in 


K 


the code and immediately following the code, the number you are dialing but 
strike the '1' in the beginning out first. If the tone does end, then punch in t 
he 
code when the tone ends. Then, it will give you another tone. Punch in the 
number you are dialing, or a '9'. If you punch in a '9' and the tone stops, then 


you messed up a little. If you punch in a tone and the tone continues, then simp 
ly 
dial then number you are calling without the '1'. 


All codes are not universal. The only type that I know of that is truly universa 
I is 
Metrophone. Almost every major city has a local Metro dialup (for Philadelphia, 


(215) 351-0100/0126) and since the codes are universal, almost every phreak has 
used them once or twice. They do not employ ANI in any outlets that I know of, 
so feel free to check through your books and call 555-1212 or, as a more devious 


manor, subscribe yourself. Then, never use your own code. That way, if they 
check up on you due to your caller log, they can usually find out that you are 
subscribed. Not only that but you could set a phreak hacker around that area 

and just let it hack away, since they usually group them, and, as a bonus, you w 
ill 

have their local dialup. 


950's. They seem like a perfectly cool phreakers dream. They are free from your 
house, from payphones, from everywhere, and they host all of the major long 
distance companies (950)1044 <MCI>, (950)1077 <Sprint>, 950-1088 <S+ylines>, 
950-1033 <US Telecom>.) Well, they aren't. They were designed for ANI. That 

is the point, end of discussion. 


A phreak dictionary. If you remember all of the things contained on that file u 
p there, 

you may have a better chance of doing whatever it is you do. 
s maybe a 

little more interesting... 


= 


This next section i 


Blue Box Plans: 


These are some blue box plans, but first, be warned, there have been 2600hz tone 


detectors out on operator trunk lines since XB4. The idea behind it is to use a 
2600hz tone 

for a few very naughty functions that can really make your day lighten up. But f 
irst, here 

are the plans, or the heart of the file: 


1100 : 6: 9 KP 
1300 : 10 KP2 
1500 : : : fee GPs 


700 : 900 :1100 :1300 :1500 


Stop! Before you diehard users start piecing those little tone tidbits together, 
there is a 

simpler method. If you have an Apple-Cat with a program like Cat's Meow IV, then 
you can 

generate the necessary tones, the 2600hz tone, the KP tone, the KP2 tone, and th 
e ST tone 


through the dial section. So if you have that I will assume you can boot it up a 

nd it works, 

and I'll do you the favor of telling you and the other users what to do with the 
blue box now 

that you have somehow constructed it. The connection to an operator is one of th 
e most 

we known and used ways of having fun with your blue box. You simply dial a TSP 
S (Traffic 
Service Positioning Station, or the operator you get when you dial '0') and blow 
a 2600hz 

tone through the line. Watch out! Do not dial this direct! After you have done t 
hat, it is 

quite simple to have fun with it. Blow a KP tone to start a call, a ST tone to s 
top it, anda 

2600hz tone to hang up. Once you have connected to it, here are some fun numbers 
to call 

with it: 


0-700-456-1000 Teleconference (free, because you are the operator!) 


(Area code)-101 Toll Switching 


(Area 
(Area 
(Area 
(Area 


(Area 


Well, 
pfu 


perator 


code)-121 Local Operator (hehe) 


code)-131 Information 


code)-141 Rate & Route 


code)-181 Coin Refund Operator 


code)-11511 Conference operator (when you dial 800-544-6363) 


those were the tone matrix controllers for the blue box and some other he 


stuff to help you to start out with. But those are only the functions with the o 


There are other k-fun things you can do with it. 
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e file 


plans, since they were once a vital part of phreaking. Another thing that every 


needs is a complete listing of all of the 800 numbers around so you can have som 


e more 


Fun: 


/-/ 800 Dialup Listings /-/ 


1-800-3 


45-0008 (6) 1-800-547-6754 (6) 


1-800-245-4890 (4) 1-800-327-9136 (4) 
1-800-526-5305 (8) 1-800-858-9000 (3) 
1-800-437-9895 (7) 1-800-245-7508 (5) 


1-800-343-1844 (4) 1-800-322-1415 (6) 


1-800-437-3478 (6) 1-800-325-7222 (6) 


All right, set Cat Hacker 1.0 on those numbers and have a fuck of a day. That is 
enough with 

800 codes, by the time this gets around to you I don't know what state those cod 
es will be 

in, but try them all out anyways and see what you get. On some 800 services now, 
they have 
an operator who wi answer and ask you for your code, and then your name. Some 
wi switch 

back and forth between voice and tone verification, you can never be quite sure 

which you 

wi be up against. 


Armed with this knowledge you should be having a pretty good time phreaking now. 
But class 

isn't over yet, there are still a couple important rules that you should know. I 
f you hear 

continual clicking on the line, then you should assume that an operator is messi 
ng with 

something, maybe even listening in on you. It is a good idea to call someone bac 
k when the 


phone starts doing that. If you were using a code, use a different code and/or s 
ervice to 
call him back. 


A good way to detect if a code has gone bad or not is to listen when the number 
has been 

dialed. If the code is bad you will probably hear the phone ringing more clearly 
and more 
quickly than if you were using a different code. If someone answers voice to it 
then you can 

immediately assume that it is an operative for whatever company you are using. T 
he famed 

'311311' code for Metro is one of those. You would have to be quite stupid to ac 


tually 

respond, because whoever you ask for the operator will always say 'He's not in r 
ight now, 

can I have him call you back?' and then they will ask for your name and phone nu 


mber. Some 
of the more sophisticated companies will actually give you a carrier on a line t 
hat is 

supposed to give you a carrier and then just have garbage flow across the screen 


would with a bad connection. That is a feeble effort to make you think that the 
code is still 

working and maybe get you to dial someone's voice, a good test for the carrier t 
rick is to 
dial a number that will give you a carrier that you have never dialed with that 
code before, 

that will allow you to determine whether the code is good or not. For our next s 
ection, a 
lighter look at some of the things that a phreak should not be without. A vocabu 
lary. 


A few months ago, it was a quite strange world for the modem people out there. B 
ut now, a 

phreaker's vocabulary is essential if you wanna make a good impression on people 
when you 

post what you know about certain subjects. 


/-/ Vocabulary /-/ 


- Do not misspell except certain exceptions: 


phone -> fone 


freak -> phreak 


- Never substitute 'z's for 's's. (i.e. codez -> codes) 


Never leave many characters after a post (i.e. Hey Dudes! #!@#@!#!@) 


- NEVER use the 'k' prefix (k-kool, k-rad, k-whatever) 


- Do not abbreviate. (I got lotsa wares w/ docs) 


- Never substitute '0' for 'o' (r0dent, 10zer). 


- Forget about ye old upper case, it looks ruggyish. 


All right, that was to relieve the tension of what is being drilled into your mi 
nds at the 

moment. Now, however, back to the teaching course. Here are some things you shou 
ld know 

about phones and billings for phones, etc. 


LATA: Local Access Transference Area. Some people who live in large cities or ar 
eas may be 
plagued by this problem. For instance, let's say you live in the 215 area code u 
nder the 542 

prefix (Ambler, Fort Washington). If you went to dial in a basic Metro code from 
that area, 
for instance, 351-0100, that might not be counted under unlimited local calling 
because it is 
out of your LATA. For some LATA's, you have to dial a '1' without the area code 
before 
you can dial the phone number. That could prove a hassle for us all if you didn' 
t realize you 
would be billed for that sort of call. In that way, sometimes, it is better to b 
e safe than 

sorry and phreak. 


The Caller Log: In ESS regions, for every household around, the phone company ha 
S 
something on you called a Caller Log. This shows every single number that you di 
aled, and 

things can be arranged so it showed every number that was calling to you. That's 
one main 

isadvantage of ESS, it is mostly computerized so a number scan could be done li 
ke that 
quite easily. Using a dialup is an easy way to screw that, and is something wort 
h 
remembering. Anyways, with the caller log, they check up and see what you dialed 
Eo ATMs 
you dialed 15 different 800 numbers that month. Soon they find that you are subs 
cribed to 

none of those companies. But that is not the only thing. Most people would imagi 
ne "But wait! 
800 numbers don't show up on my phone bill!". To those people, it is a nice thou 
ght, but 800 

numbers are picked up on the caller log until right before they are sent off to 
you. So they 

can check right up on you before they send it away and can note the fact that yo 
u fucked up 

slightly and called one too many 800 lines. 


Q 


Right now, after all of that, you should have a pretty good idea of how to grow 
up as a good 

phreak. Follow these guidelines, don't show off, and don't take unnecessary risk 
s when 

phreaking or hacking. 


122.Phrack Magazine - Vol. 3, Issue 27 by Knight Lightning 


Prologue 


If you are not already familiar with NSFnet, I would suggest that you read: "Fro 
ntiers" 
(Phrack Inc., Volume Two, Issue 24, File 4 of 13), and definitely; "NSFnet: Nati 
onal Science 

Foundation Network" (Phrack Inc., Volume Three, Issue 26, 

File 4 of 11). 


Introduction 


MIDNET is a regional computer network that is part of the NSFnet, the National 


Science Foundation Network. Currently, eleven mid-United States universities 


are connected to each other and to the NSFnet via MIDnet: 


UA - University of Arkansas at Fayetteville 
ISU - Iowa State University at Ames 
UI - University of Iowa at Iowa City 
KSU - Kansas State University at Manhattan 


KU - University of Kansas at Lawrence 


UMC - University of Missouri at Columbia 


WU - Washington University at St. Louis, Missouri 


UNL - University of Nebraska at Lincoln 


OSU - Oklahoma State University at Stillwater 


UT - University of Tulsa (Oklahoma) 


OU - University of Oklahoma at Norman 


Researchers at any of these universities that have funded grants can access the 


six supercomputer centers funded by the NSF: 


John Von Neuman Supercomputer Center 

National Center for Atmospheric Research 
Cornell National Supercomputer Facility 
National Center for Supercomputing Applications 
Pittsburgh Supercomputing Center 


San Diego Supercomputing Center 


In addition, researchers and scientists can communicate with each other over av 

ast world- 

wide computer network that includes the NSFnet, ARPAnet, CSnet, BITnet, and othe 

rs that 

you have read about in The Future Transcendent Saga. Please refer to "Frontiers" 
(Phrack 

Inc., Volume Two, Issue 24, File 4 of 13) for more details. 


MIDnet is just one of several regional computer networks that comprise the NSFne 
t 
system. Although all of these regional computer networks work the same, MIDnet i 
s the 

only one that I have direct access to and so this file is written from a MIDnet 
point of 

view. For people who have access to the other regional networks of NSFnet, the o 
nly real 

differences depicted in this file that would not apply to the other regional net 
works are the 

universities that are served by MIDnet as opposed to: 


NYSERnet in New York State 


SURAnet in the southeastern United States 


SEQSUInet in Texas 
BARRnet in the San Francisco area 


MERIT in Michigan 


(There are others that are currently being constructed.) 


These regional networks all hook into the NSFnet backbone, which is a network th 
at 

connects the six supercomputer centers. For example, a person at Kansas State Un 
iversity 

can connect with a supercomputer via MIDnet and the NSFnet backbone. That resear 
cher 
can also send mail to colleagues at the University of Delaware by using MIDnet, 
NSFnet and 
SURAnet. Each university has its own local computer network which connects on-ca 
mpus 
computers as well as providing a means to connecting to a regional network. 


Some universities are already connected to older networks such as CSnet, the ARP 
Anet and 
BITnet. In principal, any campus connected to any of these networks can access a 
nyone else 

in any other network since there are gateways between the networks. 


Gateways are specialized computers that forward network traffic, thereby connect 
ing 

networks. In practice, these wide-area networks use different networking technol 
ogy which 

make it impossible to provide full functionality across the gateways. However, m 
ail is almost 
universally supported across all gateways, so that a person at a BITnet site can 
send mai 
messages to a colleague at an ARPAnet site (or anywhere else for that matter). Y 
ou should 

already be somewhat familiar with this, but if not refer to; "Limbo To Infinity" 
(Phrack 
Inc., Volume Two, Issue 24, File 3 of 13) and "Internet Domains" (Phrack Inc., V 
olume 

Three, Issue 26, File 8 of 11) 


Computer networks rely on hardware and software that allow computers to communic 
eee that enables network communication is called a protocol. There are 
ata protocols in use today. MIDnet uses the TCP/IP protocols, also known a 
O cee of Defense) Protocol Suite. 


Other networks that use TCP/IP include ARPAnet, CSnet and the NSFnet. In fact, a 
ll the 

regional networks that are linked to the NSFnet backbone are required to use TCP 
/IP. At 

the local campus level, TCP/IP is often used, although other protocols such as I 
BM's SNA 
and DEC's DECnet are common. In order to communicate with a computer via MIDnet 

and 

the NSFnet, a computer at a campus must use TCP/IP directly or use a gateway tha 
t will 
translate its protocols into TCP/IP. 


The Internet is a world-wide computer network that is the conglomeration of most 
of the 

large wide area networks, including ARPAnet, CSnet, NSFnet, and the regionals, s 
uch as 
MIDnet. To a lesser degree, other networks such as BITnet that can send mail to 
hosts on 

these networks are included as part of the Internet. This huge network of networ 
ks, the 

Internet, as you have by now read all about in the pages of Phrack Inc., is a ra 
pidly growing 

and very complex entity that allows sophisticated communication between scientis 
ts, 

students, government officials and others. Being a part of this community is bot 
h exciting 

and challenging. 


This chapter of the Future Transcendent Saga gives a general description of the 
protocols 
and software used in MIDnet and the NSFNet. A discussion of several of the more 
commonly used networking tools is also included to enable you to make practical 
use of the 

network as soon as possible. 


The DOD Protocol Suite 


The DOD Protocol Suite includes many different protocols. Each protocol is a spe 
cification 

of how communication is to occur between computers. Computer hardware and softwa 
re 

vendors use the protocol to create programs and sometimes specialized hardware i 
n order 

to implement the network function intended by the protocol. Different implementa 
tions of 

the same protocol exist for the varied hardware and operating systems found in a 
network. 


The three most commonly used network functions are: 


Mail -- Sending and receiving messages 


File Transfer -- Sending and receiving files 


Remote Login -- Logging into a distant computer 


Of these, mail is probably the most commonly used. 


In the TCP/IP world, there are three different protocols that realize these 


functions: 

SMTP -- (Simple Mail Transfer Protocol) 
FTP -- (Fil 
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and transfer accomplish the transfer of raw information from 
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hing. However, mail messages are not identica 


tolerate some errors in transmission whereas fil 


file transfers usually occur in a secure setting (i.e. 


only ASCII characters and are sequential in structure. Fil 


L, mail and file transfer 


to files, since they ar 


LeS may co 


structures. Also, mail 


messages 


les should not contain any errors 


mail can be sent to anybody as long as their name is known). 


king to another terminal. Telnet is most often 


The users who are transfe 


know each other's names and passwords and are permitted to transfer the file, wh 


one comp 


Telnet allows a distant user to process that information, either by log 


used to 


a distant computer, but it is actually a general-purpose communication 


I 


useful over the last year. 


In some ways, 


it could be us 


of access because you can directly connect to another computer anywhe 


capabilities, 


other functions that some networks provide, including the following: 


however please note that Telnet is *NOT* Telenet. There 


Name to address translation for networ 
The current time 

Quote of the day or fortune 

Printing on a remote printer, or use o 
Submission of batch jobs for non-inter 
Dialogues and conferencing between mu 


ks, computers and people 


+ 


any other remote peripheral 
active execution 
tiple users 


Remote procedure call (i.e. Distributi 
computers) 


Some of these functions are still in the 
computer 


Transmission of voice or video informat 


ng program execution over several remote 


ion 


experimental stages and require faster 


networks than currently exist. In the future, new functions will undoubtedly be 


invented 
and existing ones improved. 


The DOD Protocol 
rk 


Suite is a 


ayered network architecture, which means that netwo 


functions are performed by different programs that work independently and in har 


mony 


with each other. Not only are there different programs but there are different p 
rotocols. 

The protocols SMTP, FTP and Telnet are described above. Protocols have been defi 
ned for 

getting the current time, the quote of the day, and for translating names. These 
protocols 

are called applications protocols because users directly interact with the progr 
ams that 

implement these protocols. 


The Transmission Control Protocol, TCP, is used by many of the application proto 
cols. Users 
almost never interact with TCP directly. TCP establishes a reliable end-to-end c 
onnection 

between two processes on remote computers. Data is sent through a network in sma 
1l 
chunks called packets to improve reliability and performance. TCP ensures that p 
ackets 

arrive in order and without errors. If a packet does have errors, TCP requests t 
hat the 

packet be retransmitted. 


In turn, TCP calls upon IP, Internet Protocol, to move the data from one network 
to 
another. IP is still not the lowest layer of the architecture, since there is us 
ually a "data 
link layer protocol" below it. This can be any of a number of different protocol 
s, two very 

common ones being X.25 and Ethernet. 


FTP, Telnet and SMTP are called “application protocols", since they are directly 
used by 
applications programs that enable users to make use of the network. Network appl 
ications 
are the actual programs that implement these protocols and provide an interface 
between 
the user and the computer. An implementation of a network protocol is a program 
or 
package of programs that provides the desired network function such as file tran 
sfer. 

Since computers differ from vendor to vendor (e.g. IBM, DEC, CDC), each computer 
must 

have its own implementation of these protocols. However, the protocols are stand 
ardized 

so that computers can interpolate over the network (i.e. Can understand and proc 
ess each 

other's data). For example, a TCP packet generated by an IBM computer can be rea 
d and 

processed by a DEC computer. 


In many instances, network applications programs use the name of the protocol. F 


or 

example, the program that transfers files may be called "FTP" and the program th 
at allows 
remote logins may be called "Telnet." Sometimes these protocols are incorporated 
into 
larger packages, as is common with SMTP. Many computers have mail programs that 
allow 
users on the same computer to send mail to each other. SMTP functions are often 
added to 

these mail programs so that users can also send and receive mail through a netwo 
rk. In 

such cases, there is no separate program called SMTP that the user can access, s$ 
ince the 

mail program provides the user interface to this network function. 


Specific implementation of network protocols, such as FTP, are tailored to the c 
omputer 

hardware and operating system on which they are used. Therefore, the exact user 
interface varies from one implementation to another. For example, the FTP protoc 
ol 

specifies a set of FTP commands which each FTP implementation must understand an 
d 

process. However, these are usually placed at a low level, often invisible to th 
e user, who is 

given a higher set of commands to use. 


These higher-level commands are not standardized so they may vary from one 
implementation of FTP to another. For some operating systems, not all of these c 
ommands 

make equal sense, such as "Change Directory," or may have different meanings. Th 
erefore 

the specific user interface that the user sees will probably differ. 


This file describes a generic implementation of the standard TCP/IP application 
protocols. 
Users must consult local documentation for specifics at their sites. 


Names and Addresses In A Network 


In DOD Protocol Suite, each network is given a unique identifying number. This n 
umber is 

assigned by a central authority, namely the Network Information Center run by SR 
I, 
abbreviated as SRI-NIC, in order to prevent more than one network from having th 
e same 
network number. For example, the ARPAnet has network number 10 while MIDnet has 
a 
longer number, namely 128.242. Each host in a network has a unique identificatio 
n so other 
hosts can specify them unambiguously. Host numbers are usually assigned by the 
organization that manages the network, rather than one central authority. Host n 
umbers do 

not need to be unique throughout the whole Internet but two hosts on the same ne 
twork 

need to have unique host numbers. 


The combination of the network number and the host number is called the IP addre 
ss of the 

host and is specified as a 32-bit binary number. All IP addresses in the Interne 
t are 
expressible as 32-bit numbers, although they are often written in dotted decimal 
notation. 

Dotted decimal notation breaks the 32-bit number into four eight-bit parts or oc 
tets and 
each octet is specified as a decimal number. For example, 00000001 is the binary 
octet 
that specifies the decimal number 1, while 11000000 specifies 192. Dotted decima 
l notation 

makes IP addresses much easier to read and remember. 


Computers in the Internet are also identified by hostnames, which are strings of 


characters, such as "phrackvax." However, IP packets must specify the 32-bit IP 
address 
instead of the hostname so some way to translating hostnames to IP addresses mus 
t exist. 


One way is to have a table of hostnames and their corresponding IP addresses, ca 
lled a 
hosttable. Nearly every TCP/IP implementation has such a hosttable, although the 


weaknesses of this method are forcing a shift to a new scheme called the domain 
name 

system. In UNIX systems, the hosttable is often called "/etc/hosts." You can usu 
ally read 

this file and find out what the IP addresses of various hosts are. Other systems 
may call 
this file by a different name and make it unavailable for public viewing. 


Users of computers are generally given accounts to which all charges for compute 
r use are 

billed. Even if computer time is free at an installation, accounts are used to d 
istinguish 

between the users and enforce file protections. The generic term "username" will 
be used 

in this file to refer to the name by which the computer account is accessed. 


In the early days of the ARPAnet which was the first network to use the TCP/IP p 
rotocols, 

computer users were identified by their username, followed by a commercial "at" 
sign (@), 


followed by the hostname on which the account existed. Networks were not given n 
ames, 
per se, although the IP address specified a network number. 


For example, "knight@phrackvax" referred to user "knight" on host "phrackvax." T 
his did 

not specify which network "phrackvax" was on, although that information could be 
obtained 

by examining the hosttable and the IP address for "phrackvax." (However, "phrack 

vax" is a 

fictitious hostname used for this presentation.) 


As time went on, every computer on the network had to have an entry in its hostt 
able for 
every other computer on the network. When several networks linked together to fo 
rm the 
Internet, the problem of maintaining this central hosttable got out of hand. The 
refore, the 
domain name scheme was introduced to split up the hosttable and make it smaller 
and easier 

to maintain. 


In the new domain name scheme, users are still identified by their usernames, bu 
t hosts are 

now identified by their hostname and any and all domains of which they are a par 
Eas Or 

example, the address "KNIGHT@UMCVMB.MISSOURI.EDU" specifies username "KNIGHT" 

on host "UMCVMB". However, host "UMCVMB" is a part of the domain "MISSOURI" " wh 
ich 

is in turn part of the domain "EDU". There are other domains in "EDU", although 
only one is 

named "MISSOURI". In the domain "MISSOURI", there is only one host named "UMCVMB 


" 
. 


However, other domains in "EDU" could theoretically have hosts named "UMCVMB" 
(although I would say that this is rather unlikely in this example). Thus the co 

mbination of 

hostname and all its domains makes it unique. The method of translating such nam 

es into IP 

addresses is no longer as straightforward as looking up the hostname in a table. 
Several 

protocols and specialized network software called nameservers and resolvers impl 
ement the 

domain name scheme. 


Not all TCP/IP implementations support domain names because it is rather new. In 
those 

cases, the local hosttable provides the only way to translate hostnames to IP ad 
dresses. 


The system manager of that computer will have to put an entry into the hosttable 
for every 

host that users may want to connect to. In some cases, users may consult the nam 
eserver 

themselves to find out the IP address for a given hostname and then use that IP 

address 

directly instead of a hostname. 


I have selected a few network hosts to demonstrate how a host system can be spec 
ified by 
both the hostname and host numerical address. Some of the nodes I have selected 
are also 
nodes on BlTnet, perhaps even some of the others that I do not make a note of du 
e a lack 
of omniscient awareness about each and every single host system in the world :-) 


Numerical BITnetHostnameLocation18.72.0.39ATHENA.MIT.EDUMass. Institute of 
Technology MIT26.0.0.73SRI-NIC.ARPADDN Network Information Center - 
36.21.0.13MACBETH.STANFORD.EDUStanford University 
236.21.0.60PORTIA.STANFORD.EDUStanford University 
2128.2.11.131ANDREW.CMU.EDUCarnegie Mellon Univ. 
ANDREW128.3.254.13LBL.GOVLawrence Berkeley Labrotories 


LBL128.6.4.7RUTGERS.RUTGERS.EDURutgers University 
2128«9.99.1CUCARD.MED.COLUMBIA.EDUColumbia University 
2128.102.18.3AMES.ARC.NASA.GOVAmes Research Center [NASA] - 
128.103.1.1HARVARD.EDUHarvard University HARVARD128.111.24.40HUB.UCSB.EDUUniv. 
Of Santa Barbara ?128.115.14.1LLL-WINKEN.LLNL.GOVLawrence Livermore Labratories 


128.143.2.7UVAARPA.VIRGINIA.EDUUniversity of Virginia 
2128.148.128.40BROWNVM.BROWN.EDUBrown University 
BROWN128.163.1«UKCC.UKY.EDUUniversity of Kentucky 
UKCC128.183.10.4NSSDCA.GSFC.NASA.GOVGoddard Space Flight Center [NASA]- 
128.186.4.18RAI.CC.FSU.EDUFlorida State University 
FSU128.206.1.1UMCVMB.MISSOURI.EDUUniv. of MissouriColumbia 
UMCVMB128.208.1.15MAX.ACS.WASHINGTON.EDUUniversity of Washington 
MAX128.228.1.2CUNYVM.CUNY.EDUCity University of New York 
UNYVM129.10.1.6NUHUB.ACS.NORTHEASTERN.EDUNortheastern University 
UHUB131.151.1.4UMRVMA.UMR.EDUUniversity of Missouri Rolla 
UMRVMA192.9.9.1SUN.COMSun Microsystems, Inc. -192.33.18.30VM1.NODAK.EDUNorth 
akota State Univ. NDSUVM1192.33.18«0PLAINS.NODAK.EDUNorth Dakota State Univ. 
NDSUVAX 


O 


Please Note: Not every system on BITnet has an IP address. Likewise, not every s 


ystem 

that has an IP address is on BlTnet. Also, while some locations like Stanford Un 
iversity 

may have nodes on BITnet and have hosts on the IP as well, this does not necessa 
rily imply 


that the systems on BITnet and on IP (the EDU domain in this case) are the same 
systems. 


Attempts to gain unauthorized access to systems on the internet are not tolerate 
d and is 

legally a federal offense. At some hosts, they take this very seriously, especia 
lly the 

government hosts such as NASA's Goddard Space Flight Center, where they do not m 
ind 

telling you so at the main prompt when you connect to their system. 


However, some nodes are public access to an extent. The DDN Network Information 

Center 

can be used by anyone. The server and database there have proven to be an invalu 
able 

source of information when locating people, systems, and other information that 

is related 

to the Internet. 


Telnet 


Remote login refers to logging in to a remote computer from a terminal connected 

to a loca 
computer. Telnet is the standard protocol in the DOD Protocol Suite for accompli 
shing 
this. The "rlogin" program, provided with Berkeley UNIX systems and some other s 
ystems, 


also enables remote login. 


For purposes of discussion, the "local computer" is the computer to which your t 
erminal is 

directly connected while the "remote computer" is the computer on the network to 
which 
you are communicating and to which your terminal is *NOT* directly connected. 


Since some computers use a different method of attaching terminals to computers, 
a 

better definition would be the following: The "local computer" is the computer t 

hat you are 

currently using and the "remote computer" is the computer on the network with wh 
ich you 


are or will be communicating. Note that the terms "host" and "computer" are syno 
nymous in 
the following discussion. 


To use Telnet, simply enter the command: TELNET 


The prompt that Telnet gives is: Telnet> 


(However, you can specify where you want to Telnet to immediately and bypass the 
prompts 
and other delays by issuing the command: TELNET 


[location].) 


There is help available by typing in ?. This prints a list of all the valid 


subcommands that Telnet provides with a one-line explanation. 


Telnet> ? 


To connect to another computer, use the open subcommand to open a connection 
to that computer. For example, to connect to the host "UMCVMB.MISSOURI.EDU", 


do "open umcvmb.missouri.edu" 


Telnet will resolve (i.e. Translate, the hostname "umcvmb.missouri.edu" into an 


IP address and will send a packet to that host requesting login. If the remote 


host decides to let you attempt a login, it prompts you for your username and pa 
ssword. If 
the host does not respond, Telnet will "time out" (i.e. Wait for a reasonable am 
ount of time 
such as 20 seconds) and then terminate with a message such as "Host not respondi 
ng." 


If your computer does not have an entry for a remote host in its hosttable and i 
t cannot 

resolve the name, you can use the IP address explicitly in the telnet command. F 
or example, 


TELNET 26.0.0.73 (Note: This is the IP address for the DDN Network Information C 


enter 
[SRI-NIC.ARPA] ) 


If you are successful in logging in, your terminal is connected to the remote ho 
st. For all 

intents and purposes, your terminal is directly hard-wired to that host and you 
should be 

able to do anything on your remote terminal that you can do at any local termina 
There are 

a few exceptions to this rule, however. 


Telnet provides a network escape character, such as CONTROL-T. You can find out 
what 
the escape character is by entering the "status" subcommand: 


Telnet> status 


You can change the escape character by entering the "escape" subcommand: 


Telnet> escap 


When you type in the escape character, the Telnet prompt returns to your screen 
and you 

can enter subcommands. For example, to break the connection, which usually logs 
you off 

the remote host, enter the subcommand "quit": 


Telnet> quit 


Your Telnet connection usually breaks when you log off the remote host, so the " 
quit" 
subcommand is not usually used to log off. 


When you are logged in to a remote computer via Telnet, remember that there is a 
time 

delay between your local computer and the remote one. This often becomes apparen 
t to 
users when scrolling a long file across the terminal screen and they wish to can 
cel the 
scrolling by typing CONTROL-C or something similar. After typing the special con 
trol 
character, the scrolling continues. The special control character takes a certai 
n amount of 
time to reach the remote computer which is still scrolling information. Thus res 
ponse from 

the remote computer will not likely be as quick as response from a local compute 
r. Once you 
are remotely logged on, the computer you are logged on to effectively becomes yo 
ur "local 
computer," even though your original "local computer" still considers you logged 
on. You can 
log on to a third computer which would then become your "local computer" and so 
on. AS you 

log out of each session, your previous session becomes active again. 


File Transfer 


FTP is the program that allows files to be sent from one computer to another. 


"FTP" stands for "File Transfer Protocol". 


When you start using FTP, a communications channel with another computer on the 
network 

is opened. For example, to start using FTP and initiate a file transfer session 
with a 

computer on the network called "UMCVMB", you would issue the following subcomman 
d: 


FTP UMCVMB.MISSOURI.EDU 


Host "UMCVMB" will prompt you for an account name and password. If your login is 
correct, 

FTP will tell you so, otherwise it will say "login incorrect." Try again or abor 
t the FTP 

program. (This is usually done by typing a special control character such as CON 

TROL-C. 

The "program abort" character varies from system to system.) 


Next you will see the FTP prompt, which is: 


Ftp> 


There are a number of subcommands of FTP. The subcommand "?" will list these com 
mands 
and a brief description of each one. 


You can initiate a file transfer in either direction with FTP, either from the r 
emote host or 
to the remote host. The "get" subcommand initiates a file transfer from the remo 
te host 
(i.e. Tells the remote computer to send the file to the local computer [the one 
on which you 


issued the "ftp" command]). Simply enter "get" and FTP will prompt you for the r 
emote 
host's file name and the (new) local host's file name. Example: 


Ftp> get 


Remote file name? 


theirfile 


local file name? 


myfile 


You can abbreviate this by typing both file names on the same line as the "get" 
subcommand. 
If you do not specify a local file name, the new local file wi be called the s 
ame thing as the 
remote file. Valid FTP subcommands to get a file include the following: 


get theirfile myfile 


get doc.x25 


The "put" subcommand works in a similar fashion and is used to send a file from 
the loca 
computer to the remote computer. Enter the command "put" and FTP will prompt you 
for 
the local file name and then the remote file name. If the transfer cannot be don 
e because 

the file doesn't exist or for some other reason, FTP will print an error message 


There are a number of other subcommands in FTP that allow you to do many more th 
ings. 

Not all of these are standard so consult your local documentation or type a ques 
tion mark at 

the FTP prompt. Some functions often built into FTP include the ability to look 

at files 
before getting or putting them, the ability to change directories, the ability t 
o delete files 

on the remote computer, and the ability to list the directory on the remote host 


An intriguing capability of many FTP implementations is "third party transfers." 
For 
example, if you are logged on computer A and you want to cause computer B to sen 


da file to 

computer C, you can use FTP to connect to computer B and use the "rmtsend" comma 
nd. Of 

course, you have to know usernames and passwords on all three computers, since F 
TP never 

allows you to peek into someone's directory and files unless you know their user 
name and 

password. 


H 


he "cd" subcommand changes your working directory on the remote host. The "lcd" 


subcommand changes the directory on the local host. For UNIX systems, the meanin 
g of 

these subcommands is obvious. Other systems, especially those that do not have d 
irectory- 

structured file system, may not implement these commands or may implement them i 
na 

different manner. 


The "dir" and "ls" subcommands do the same thing, namely list the files in the w 
orking 
directory of the remote host. 


The "list" subcommand shows the contents of a file without actually putting it i 
nto a file on 
the local computer. This would be helpful if you just wanted to inspect a file. 
You could 


interrupt it before it reached the end of the file by typing CONTROL-C or some o 
ther 
special character. This is dependent on your FTP implementation. 


The "delete" command can delete files on the remote host. You can also make and 
remove 

directories on the remote host with "mkdir" and "rmdir". The "status" subcommand 
will tell 

you if you are connected and with whom and what the state of all your options ar 
e. 


If you are transferring binary files or files with any non-printable characters, 
turn binary 
mode on by entering the "binary" subcommand: 


binary 


To resume non-binary transfers, enter the "ascii" subcommand. 


Transferring a number of files can be done easily by using "mput" (multiple put) 
and "mget" 
(multiple get). For example, to get every file in a particular directory, first 
issue a "cd" 

command to change to that directory and then a "mget" command with an asterisk t 
O 
indicate every file: 


cd somedirectory 


mget * 


When you are done, use the "close" subcommand to break the communications link. 
You will 

still be in FTP, so you must use the "bye" subcommand to exit FTP and return to 
the 

command level. The "quit" subcommand will close the connection and exit from FTP 
at the 

same time. 


Mail 


Mail is the simplest network facility to use in many ways. All you have to do is 
to create your 


message, which can be done with a file editor or on the spur of the moment, and 
then send 
it. Unlike FTP and Telnet, you do not need to know the password of the username 


on the 

remote computer. This is so because you cannot change or access the files of the 
remote 

user nor can you use their account to run programs. All you can do is to send a 

message. 


There is probably a program on your local computer which does mail between users 
on that 
computer. Such a program is called a mailer. This may or may not be the way to s 


end or 


e 


receive mail from other computers on the network, although integrated mailers ar 


more 


and more common. UNIX mailers will be used as an example in this discussion. 


Note that the protocol which is used to send and receive mail over a TCP/IP netw 
ork is 
called SMTP, the "Simple Mail Transfer Protocol." Typically, you will not use an 


Y 


program 


called SMTP, but rather your local mail program. 


UNIX mailers are usually used by invoking a program named "mail". To receive new 


mail, 


simply type "mail". There are several varieties of UNIX mailers in existence. Co 
nsult your 


local documentation for details. For example, the command "man mail" prints out 


the 


manual 


pages for the mail program on your computer. 


To send mail, you usually specify the address of the recipient on the mail comma 


nd. 


For 


example: "mail knight@umcvmb.missouri.edu" will send the following message to us 
ername 
"knight" on host "umcvmb". 


You can usually type in your message one line at a time, pressing RETURN after e 
ach line 

and typing CONTROL-D to end the message. Other facilities to include already-exi 
sting 


similar 
to the following to include a file in your current mail message: 


r myfile 


files sometimes exist. For example, Berkeley UNIX's allow you to enter commands 


In this example, the contents of "myfile" are inserted into the message at this 
point. 


Most UNIX systems allow you to send a file through the mail by using input redir 
ection. 


For example: 


mail knight@umcvmb.missouri.edu < myfile 


In this 


umcvmb." 


xample, the contents of "myfile" are sent as a message to "knight" on " 


Note that in many UNIX systems the only distinction between mail bound for anoth 


the same computer and another user on a remote computer is simply the address 


specified. That is, there is no hostname for local recipients. Otherwise, mail f 


exactly the same way. 


er user 
on 
e 
unctions in 
a 
ows 
whe 
the user 


This is common for integrated mail packages. The system kn 


ther to send the mail locally or through the network based on the address and 


is shielded from any other details. 


"The Quest For Knowledge Is Without End..." 


123.Phrack Magazine - Vol. 3, Issue 27 by Knight Lightning 


Prologue For None VMS Users 


DECnet is the network for DEC machines, in most cases you can say VAX's. DECnet 
allows 
you to do: 


e-mail 

file transfer 
remote login 
remote command 
remote job entry 
PHONE 


PHONE is an interactive communication between users and is equal to TALK on UNIX 
or a 
"deluxe"-CHAT on VM/CMS. 


BELWUE, the university network of the state Baden-Wuerttemberg in West Germany 
contains (besides other networks) a DECnet with about 400 VAX's. On every VAX th 
ere is 
standard-account called DECNET with pw:= DECNET, which is not reachable via remo 
te 
ogin. This account is provided for several DECnet-Utilities and as a pseudo-gue 
st-account. 
[The DECNET-account has very restricted privileges: You cannot edit a file or mak 
e another 

remote login. 


The HELP is equipped by the system and is similar to the MAN command on UNIX. 


More information on DECnet can be found in "Looking Around In DECnet" by Deep Th 
ought 
in this very issue of Phrack Inc. 


Here, at the University of Ulm, we have an *incredibly* ignorant computer center 
staff, 

with an even bigger lack of system-literature (besides the 80kg of VAX/VMS-manua 

ls). 

The active may search for information by himself, which is over the level of "ru 


"FORTRAN," or "logout." My good luck that I have other accounts in the BELWUE-DE 
Cnet, 
where more information is offered for the users. I am a regular student in Ulm a 


nd all my 

accounts are completely legal and corresponding to the German laws. I don't call 
myself a 

"hacker," I feel more like a "user" (...it's more a defining-problem). 


In the HELP-menu in a host in Tuebingen I found the file netdcl.com and the corr 
esponding 
explanation, which sends commands to the DECNET-Account of other VAX's and execu 
tes 
them there (remote command). The explanation in the HELP-menu was idiot-proof -- 


therefore for me, too :-) 


ith the command "$ mcr ncp show known nodes" you can obtain a list of all netwi 
e active 
AX's, as is generally known, and so I pinged all these VAX's to look for more i 
formation 
or a knowledge-thirsty user. With "help", "dir" and other similar commands I lo 
k around 
n those DECnet accounts, always watching for topics related to the BELWUE-netwo 


k. It's 


saz 


R OO hB 


a pity, that 2/3 of all VAX's have locked the DECNET-Account for NETDCL.COM. 
ir 


The 


system managers are probably afraid of unauthorized access, but I cannot imagi 


how 


ne 


there could be such an unauthorized access, because you cannot log on this accou 


nt -- no 
chance for trojan horses, etc. 


Some system managers called me back after I visited their VAX to chat with me 
out the 


ab 


network and asked me if they could help me in any way. One sysop from Stuttgart 


even sent 
me a version of NETDCL.COM for the ULTRIX operation system. 


Then, after a month, the HORROR came over me in shape of a the following mail: 


From: TUEBINGEN::SYSTEM 31-MAY-1989 15:31:11.38 
To: FRAMSTAG 
CC: 


Subj: don't make any crap, or you'll be kicked out! 


From: ITTGPX::SYSTEM 29-MAY-1989 16:46 


To: TUEBINGEN: : SYSTEM 


Subj: System-breaking-in 01-May-1989 


To the system manager of the Computer TUEBINGEN, 


On May lst 1989 we had a System-breaking-in in our DECNET-account, which started 
from 
your machine. By help of our accounting we ascertained your user FRAMSTAG to hav 
e 
emulated an interactive log-on on our backbone-node and on every machine of our 
VAX- 
cluster with the "trojan horse" NETDCL.COM. Give us this user's name and address 
and 
dear up the occurrence completely. We point out that the user is punishable. In 
case of 
repetition we would be forced to take corresponding measures. We will check whet 
her our 
system got injured. If not, this time we will disregard any measure. Inform us v 
ia DECnet 
about your investigation results -- we are attainable by the nodenumber 1084::sy 
stem 


Dipl.-Ing. Michael Hager 


My system manager threatened me with the deleting of my account, if I would not 


immediately enlighten the affair. *Gulp*! I was conscious about my innocence, bu 
t how to 
tell it to the others? I explained, step by step, everything to my system manage 
r. He then 


understood after a while, but the criminal procedure still hovered over me... so 
, I took 
quickly to my keyboard, to compose file of explanations and to send it to that a 


ngry system 

manager in Stuttgart (node 1084 is an institute there). But no way out: He had r 
un out of 
disk quota and my explanation-mail sailed into the nirwana: 


$ mail explanation 


To: 1084::system 

SMAIL-E, error sending to user SYSTEM at 1084 
SMAIL-E-OPENOUT, error opening 
SYSSSYSROOT: [SYSMGR] MATLS00040092594FD194.MAT; 


as output 


-RMS-E-CRE, ACP file create failed 


-SYSTEM-F-EXDISKQUOTA, disk quota exceeded 


Also the attempt of a connection with the PHONE-facility failed: In his borderle 
ss hacker- 

paranoia, he cut off his PHONE... and nowhere is a list with the REAL-addresses 
of the 

virtual DECnet-addresses available (to prevent hacking). Now I stood there with 
the brand 

"DANGEROUS HACKER!" and I had no chance to vindicate myself. I poured out my tro 
ubles 

to an acquaintance of mine, who is a sysop in the computer-center in Freiburg. H 
e asked 

other sysops and managers thru the whole BELWUE-network until someone gave him a 


telephone number after a few days -- and that was the right one! 


I phoned to this Hager and told him what I had done with his DECnet-account and 
also 

what NOT. I wanted to know which crime I had committed. He promptly canceled all 
of his 

reproaches, but he did not excuse his defames incriminations. I entreated him to 
inform my 

system manager in Tuebingen that I have done nothing illegal and to stop him fro 

m erasing 

my account. This happens already to a fellow student of 
r was also 
guilty). He promised me that he would officially cancel his reproaches. 


mine (in this case, Hage 


After over a week this doesn't happen (I'm allowed to use my account further on 
Jes in 
return for it, I received a new mail from Hager on another account of mine: 


From: 1084::HAGER 1-JUN-1989 12:51 
To: 50180::STUD_11 


Subj: System-breaking-in 


On June 1st 1989 you have committed a system-breaking-in on at least one of our 
VAX's. 

We were able to register this occurrence. We would be forced to take further mea 
sure if 

you did not dear up the occurrence completely until June 6th. 


Of course the expenses involved would be imposed on you. Hence enlightenment mus 
t be in 
your own interest. 


We are attainable via DECnet-mail with the address 1084::HAGER or via following 


address: 


Institut fuer Technische Thermodynamik und Thermische Verfahrenstechnik 


Dipl.-Ing. M. Hager Tel.: 0711/685-6109 


Dipl.-Ing. M. Mrzyglod Tel.: 0711/685-3398 


Pfaffenwaldring 9/10-1 


7000 Stuttgart-80 


M. Hager 


M. Mrzyglod 


This was the reaction of my attempt: "S PHONE 1084::SYSTEM". I have not answered 
to 
this mail. I AM SICK OF IT! 
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ACSNET 


Australian Computer Science Network (ACSNET), also known as Oz, has its gateway 
through 

the CSNET node munnari.oz.au and if you cannot directly mail to the oz.au domain 
, try 

either usernamesmunnari.oz.au@UUNET.UU.NET or munnari! username@UUNET.UU.NET. 


AT&T MAIL 


Qh 


AT 
il 
equivalent. 
d problems 
having mai 
and the 


[ Mail is a mailing service of AT&T, probably what you might ca 


It is available on the UUCP network as node name attmai 


it's MCI-Ma 


but I've ha 


get through. Apparently, it does cost money to mail to this service 


surrounding nodes are not willing to pick up the tab for the ingoing mail, or at 


least, this has 


seemingly been the case thus far. 


lattmail!user 
would work. 


AT&T recently announced six new 
electronic mail services in the 
e US, AT&T 

Mail is now interconnected with 
email, 

allowing users of both services 
f these 

interconnections, the AT&T Mail 


to 
exchange messages with users of 


Compan 


Telephone 
Co.ELISAFinlandDialcomDia 
00France 


The in 
e form 


at, 


yE-Mail NameCountryTeleDeltal 
CanadaEnvoyl00CanadaDACOMDACOM MHSKoreaP&1 


comUSATelenetTe 


I be 


lieve, though, that perhaps routing to att 


X.400 interconnections between AT&T Mail and 


US, Korea, 


Sweden, 


Australia, and Finland. In th 


Telenet Communications Corporation's service, Te 


to exchange messages easily. With the addition o 


Gateway 400 Service allows AT&T Mail subscribers 


the following electronic messaging systems: 


TeDe 400Sweden 


[-Te 


eM 


OTCMPS400AustraliaTelecom- 


ilNet 400FinlandHelsinki 


ema 


w% 


i lU 


terconnections are based on the X.400 stan 


SAKDDMessaviaJapanTranspacATLAS4 


dard, a set of guidelines for th 


delivery and receipt of electronic messages recommended by an international stan 


dards 


committee the CCITT. International X.400 messages incur a surcharge. They are: 


To Canada: 
Per note: $.05 


Per message unit: $.10 


To other international locations: 


Per note: $.20 


Per message unit: $«0 


There is no surcharge for X.400 messages within the US The following are contact 
s to 

speak with about mailing through these mentioned networks. Other questions can b 
e 
directed through AT&T Mail's toll-free number, 1-800-624-5672. 


MHS Gateway: mhs!atlas MHS Gateway: mhs!dacom 
Administrator: Bernard Tardieu Administrator: Bob Nicholson 
Transpac AT&T 

Phone: 3399283203 Morristown, NJ 07960 


Phone: +1 201 644 1838 


MHS Gateway: mhs!dialcom MHS Gateway: mhs!elisa 


Administrator: Mr. Laraman Administrator: Ulla 


Karajalainen 


Dialcom Nokia Data 


South Plainfield, NJ 07080 Phone: 01135804371 


Phone: +1 441 493 3843 


MHS Gateway: mhs!envoy MHS Gateway: mhs!kdd 
Administrator: Kin C. Ma Administrator: Shigeo Lwase 
Telecom Canada Kokusai Denshin Denwa CO. 


Phone: +1 613 567 7584 Phone: 8133477419 


MHS Gateway: mhs!mailnet MHS Gateway: mhs!otc 


Administrator: Kari Aakala Administrator: Gary W. 


Krumbine 
Gen Directorate Of Post & AT&T Information Systems 
Phone: 35806921730 Lincroft, NJ 07738 


Phone: +1 201 576 2658 


MHS Gateway: mhs!telemail MHS Gateway: mhs 
Administrator: Jim Kelsay Administrator: AT&T Mail MHS 
GTE Telenet Comm Corp Gateway 

Reston, VA 22096 AT&T 

Phone: +1 703 689 6034 Lincroft, NJ 08838 


Phone: +1 800 624 5672 


CMR 


Previously known as Intermail, the Commercial Mail Relay (CMR) Service is a mail 
relay 

service between the Internet and three commercial electronic mail systems: US 
Sprint/Telenet, MCI-Mail, and DIALCOM systems (i.e. Compmail, NSFMAIL, and USDA- 

MAIL). 


An important note: The only requirement for using this mail gateway is that the 
work 
conducted must be DARPA sponsored research and other approved government busines 


S. 
Basically, this means that unless you've got some government-related business, y 
ou're not 

supposed to be using this gateway. Regardless, it would be very difficult for th 
em to screen 

everything that goes through their gateway. Before I understood the requirements 
of this 

ateway, I was sending to a user of MCI-Mail and was not contacted about any pro 
Lems 
ith that communication. Unfortunately, I mistyped the MCI-Mail address on one o 
the 
letters and that letter ended up getting read by system administrators who then 
inf 


mh & o Q 


formed 

me that I was not to be using that system, as well as the fact that they would 1 
ike to bill me 

for using it. That was an interesting thought on their part anyway, but do note 
that using 

this service does incur charges. 


The CMR mailbox address in each system corresponds to the label: 


Telemail: [Intermail/USCISI] TELEMAIL/USA 


MCI-Mail: Intermail or 107-8239 


CompMail: Intermail or CMP0817 


TELEMATL: 


BARNOC user (directly on Telemail) 


BARNOC/LODH user/organization (directly on Telemail) 


[BARNOC/LODH] TELEMAIL/USA 


[user/organization]system branch/country 


123-4567 seven digit address 


Everett T. Bowens person's name (must be unique!) 


COMPMATL: 

CMP0123 three letters followed by three or four digits 
S.Cooper initial, then "." and then last name 

134:CMP0123 domain, then ":" and then combination system and 


account number 


NSFMATL: 
NSF0123 three letters followed by three or four digits 


A.Phillips initial, then "." and then last name 


157:NSF0123 domain, then ":" and then combination system and 


account number 


USDAMATL: 


AGS0123 three letters followed by three or four digits 


P.Shifter initial, then "." and then last name 


157:AGS0123 domain, then ":" and then combination system and 


account number 


The following are other Telenet system branches/countries that can be mailed to: 


TELEMAIL/USA NASAMAIL/USA MAIL/USA TELEMEMO/AUSTRALIA 
ATI/JAPAN PIPMAIL/ROC DGC/USA FAAMAIL/USA 
GSFC/USA GTEMAIL/USA TM11/USA TNET.TELEMAIL/USA 


USDA/USA 


Note: OMNET's ScienceNet is on the Telenet system MAIL/USA and to mail to it, th 
e 
format would be [A.MAILBOX/OMNET]MAIL/USA. The following are available subdivisi 
ons 

of OMNET: 


AIR Atmospheric Sciences 


NSF-Mail: Intermail or NSF153 


USDA-Mail: Intermail or AGS9999 


Addressing examples for each e-mail system are as follows: 


MCIMAIL: 


EARTH Solid Earth Sciences 


LIFE Life Sciences 
OCEAN Ocean Sciences 
POLAR Interdisciplinary Polar Studies 


SPACE Space Science and Remote Sensing 


The following is a list of DIALCOM systems available in the listed countries wit 
h their 
domain and system numbers: 


Service NameCountryDomain NumberSystem NumberKeylink-DialcomAustralia6007, 08, 
O09DialcomCanada2020, 21, 22, 23, 24DPT 
DatabooksDenmark12471TeleboxFinland12762TeleboxWest Germany3015, 16DialcomHong 
Kong8088, 89EirmailIreland10074GoldnetIsrael5005, O6MastermailItaly13065, 
67MastermailiItalyl66, 68DialcomJapan7013, 14DialcomKoreal52Telecom 
GoldMaltal0075DialcomMexicol52MemocomNetherlands12427, 28, 
29MemocomNetherlands155StarnetNew Zealand6401, 02DialcomPuerto 
1coo825TeleboxSingapore8810, 11, 12DialcomTaiwan152Telecom GoldUnited 
ingdom10001, 04, 17, 80-89DIALCOMUSA129-34, 37, 38, 41-59, 61-63, 90-99 


N 


NOTE: 


You can also mail to username@NASAMAIL.NASA.GOV or 
username@GSFCMAIL.NASA.GOV instead of going through the CMR gateway to mail to 
NASAMATL or GSFCMAIL. 


For more information and instructions on how to use CMR, send a message to the u 
ser 
support group at intermail-regquest@intermail.isi.edu (you'll get basically what 
I've listed 
plus maybe a bit more). Please read Chapter 3 of The Future Transcendent Saga (L 
imbo to 
Infinity) for specifics on mailing to these destination mailing systems. 


COMPUSERVE 


CompuServe is well known for its games and conferences. It does, though, have ma 
a RR Now, they have developed their own Internet domain, called COMPUSERV 
raran atively new and mail can be routed through either TUT.CIS.OHIO-STATE.ED 
E 


Example: usersCOMPUSERVE.COM@TUT.CIS.OHIO-STATE.EDU or replace 


TUT.CIS. 


The Comp 
e. It is 
actually 
ch opera 
via comm 
t jobs e 
to go in 


OHIO-STATE.EDU with NORTHWESTERN.ARPA) . 


uServe link appears to be a polled UUCP connection at the gateway machin 


managed via a set of shell scripts and a comm utility called xcomm, whi 
tes 
and scripts built on the fly by the shell scripts during analysis of wha 
xist 

to and out of CompuServe. 


CompuServe subscriber accounts of the form 7xxxx, yyyy can be addressed as 


7XXXX. VV 
mes 

in the c 
"Sinet:u 
eway:" i 


yy@compuserve.com. CompuServe employees can be addressed by their userna 


si.compuserve.com subdomain. CIS subscribers write mail to 
ser@host.domain" to mail to users on the Wide-Area Networks, where ">gat 
s 


CompuServe's internal gateway access syntax. The gateway generates fully-RFC-com 
pliant 
headers. 


To fully extrapolate -- from the CompuServe side, you would use their EasyPlex m 
ail system 

to send mail to someone in BITNET or the Internet. For example, to send me mail 
at my 
Bitnet ID, you would address it to: 


INET :C488869SUMCVMB. BITNET@CUNYVM. CUNY .EDU 


Or to my Internet ID: 


INET :C488869@UMCVMB.MISSOURI.EDU 


Now, if you have a BITNET to Internet userid, this is a silly thing to do, since 
your connect 

time to CompuServe costs you money. However, you can use this information to let 
people on 

CompuServe contact YOU. CompuServe Customer Service says that there is no charge 
to 

either receive or send a message to the Internet or BITNET. 


DASNET 


DASnet is a smaller network that connects to the Wide-Area Networks but charges 
ae service. DASnet subscribers get charged for both mail to users on other ne 
AND mail for them from users of other networks. The following is a brief descrip 
o some of which was taken from their promotional text letter. 


DASnet allows you to exchange electronic mail with people on more than 20 system 
SAA that are interconnected with DASnet. One of the drawbacks, though, is t 
artes being subscribed to these services, you must then subscribe to DASnet, whi 
eee cost. Members of Wide-Area networks can subscribe to DASnet too. Some o 
ok and systems reachable through DASnet include the following: 


ABA/net, ATT Mail, BIX (Byte Information eXchange), DASnet Network, Dialcom, EIE 
S, 
EasyLink, Envoy 100, FAX, GeoMail, INET, MCI Mail, NWI, PeaceNet/EcoNet, Portal 
Communications, The Meta Network, The Source, Telemail, ATI's Telemail (Japan), 
Telex, 
TWICS (Japan), UNISON, UUCP, The WELL, and Domains (i.e. ".COM" and ".EDU" etc.) 


New systems are added all of the time. As of the writing of this file, Connect, 
GoverNET, 


MacNET, and The American Institute of Physics PI-MAIL are soon to be connected. 


You can get various accounts on DASnet including: 


Corporate Accounts -- If your organization wants more than one individual 
subscription. 
Site Subscriptions -- If you want DASnet to link directly to your organization's 


electronic mail system. 


To send e-mail through DASnet, you send the message to the DASnet account on you 
r home 

system. You receive e-mail at your mailbox, as you do now. On the Wide-Area Netw 
orks, you 


send mail to XB.DAS@STANFORD.BITNET. On the Subject: line, you type the DASnet 


address in brackets and then the usernam 


can be 


expressed after the username separated by a "!" (Exampl 


'How's 
Phrack?). 


just outside 


of them. The real subject 


e: Subject: [0756TK] randy 


The only disadvantage of using DASnet as opposed to Wide-Area networks is the co 


st. 


Subscription costs as of 3/3/89 cost $4.75 per month or $5.75 per month for host 


s that 
are outside of the USA 


You are also charged for each message that you send. If you are corresponding wi 


th 


someone who is not a DASnet subscriber, THEIR MAIL TO YOU is billed to your acco 


unt. 


The following is an abbreviated cost list for mailing to the different services 


of DASnet: 


PARTIAL List DASnet Cost DASnet Cost 


of Services 1st 1000 Each Additional 1000 


Linked by DASnet (e-mail) Characters Characters: 


INET, MacNET, PeaceNet, NOTE: 20 lines 


Unison, UUCP*, Domains, .21 .11 of text is app. 


e.g. .COM, .EDU* 1000 characters. 


Dialcom--Any "host" in US .36 .25 


Dialcom--Hosts outside US .93 .83 


EasyLink (From EasyLink) .21 .11 


(To EasyLink) «5 .23 


US FAX (international avail.) .79 .37 


GeoMail--Any "host" in US .21 .11 


GeoMail--Hosts outside US .74 .63 


MCI (from MCI) .21 .11 


(to MCI) .78 .25 


(Paper mail - USA) 2.31 .21 


Telemail .36 .25 


W.U. Telex--United States 1.79 1.63 


(You can also send Telexes outside the US) 


TWICS--Japan .89 .47 


* The charges given here are to the gateway to the network. The DASnet user is 
not 
charged for transmission on the network itself. 


Subscribers to DASnet get a free DASnet Network Directory as well as a listing i 
n the 

directory, and the ability to order optional DASnet services like auto-porting o 
r DASnet 
Telex Service which gives you your own Telex number and answerback for $8.40 am 
onth at 

this time. 


DASnet is a registered trademark of DA Systems, Inc. 


DA Systems, Inc. 

1503 E. Campbell Ave. 
Campbell, CA 95008 
408-559-7434 


TELEX: 910 380-3530 


The following two sections on PeaceNet and AppleLink are in association with DAS 
net as 
this network is what is used to connect. 
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Introduction: 


After reading the earlier renditions of schematics for the Pearl Box, I decided 
that there 
was an easier and cheaper way of doing the same thing with an IC and parts you p 
robably 
have just laying around the house. 


What Is A Pearl Box and Why Do I Want One? 


A Pearl Box is a tone generating device that is used to make a wide range of sin 
gle tones. 
Therefore, it would be very easy to modify this basic design to make a Blue Box 


by making 2 
Pearl Boxes and joining them together in some fashion. 


A Pearl Box can be used to create any tone you wish that other boxes may not. It 
also has a 

tone sweep option that can be used for numerous things like detecting different 
types of 

phone tapping devices. 


Parts List: 


CD4049 RCA integrated circuit 
.1 uF disk capacitor 

1 uF 16V electrolitic capacitor 
1K resistor 

10M resistor 

1Meg pot 
1 
S 


N914 diode 
ome SPST momentary push-button switches 


1 SPDT toggle switch 
9 Volt battery & clip and miscellaneous stuff you should have laying around the 
house. 


State-of-the-Art-Text Schematic: 


+ 16V luF - 
| | 
fae i TP E 
| | | |/| 8o0hms 
[e] AEN E DON L 
9 10 11 12 13 14 15 16 | 1/1] I_I\ 
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DY hn oo A = Gh 81 [ee 
a Pe I me Ws [-] 
K [b] 
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Fe! 
L INITA te fE] 
KA [+] 
I\ | 
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10M | | 
LENINA N 
| | 
___i|{___| | <-- These 2 wires to the center pol 
| | | of switch. 
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There are many ways of getting copies of files from a remote system that you do 
not have 

permission to read or an account on login on to and access them through. Many 
administrators do not even bother to restrict many access points that you can us 
e. 


Here are the simplest ways: 


Use uucp(1) [Trivial File Transfer Protocol] to retrieve a copy of a file if you 
are running on 
an Internet based network. 


Abuse uucp(1) [Unix to Unix Copy Program] to retrieve a copy of a file if uucp c 
onnections 
are running on that system. 


Access one of many known security loopholes. 


In the following examples, we will use the passwd file as the file to acquire si 
nce it is a 
readable file that can be found on most systems that these attacks are valid on. 


Method A : 


First start the tftp program: 


Enter the command: 


tftp 


[You have the following prompt: ] 


tfitp> 


The next step is to connect to the system that you wish to retrieve files from. 
At the tftp, 


type: 


tftp> connect other.system.com 


Now request the file you wish to get a copy of (in our case, the passwd file /et 
c/passwd ): 


tftp> get /etc/passwd /tmp/passwd 


[You should see something that looks like the following:] 


Received 185659 bytes in 22 seconds. 


Now exit the tftp program with the "quit" command: 


tftp> quit 


You should now have a copy of other.system.com's passwd file in your directory. 


NOTE: Some Unix systems' tftp programs have a different syntax. The above was te 
sted 
under SunOS 4.0 


For example, on Apollos, the syntax is: 


tftp -{glg!|plrlw} <local file> <host> <foreign file> [netascii| image] 


Thus you must use the command: 


tftp -g password_file networked-host /etc/passwd 


Consult your local "man" pages for more info (or in other words RTFM). 


At the end of this article, I will include a shell script that will snarf a pass 
word file from a 
remote host. To use it type: 


gpw system_name 


Method B : 


Assuming we are getting the file /etc/passwd from the system uusucker, and our s 
ystem 

has a direct uucp connection to that system, it is possible to request a copy of 
the file 

through the uucp links. The following command will request that a copy of the pa 
sswd file 

be copied into uucp's home directory /usr/spool/uucppublic : 


uucp -m uusucker!/etc/passwd '>uucp/uusucker_passwd' 


The flag "-m" means you will be notified by mail when the transfer is completed. 


Method C: 


The third possible way to access the desired file requires that you have the lo 
gin 
permission to the system. 


In this case we will utilize a well-known bug in Unix's sendmail daemon. 


The sendmail program has and option "-C" in which you can specify the configurat 
ion file to 

use (by default this file is /usr/lib/sendmail.cf or /etc/sendmail.cf). It shoul 
d also be 

noted that the diagnostics outputted by sendmail contain the offending lines of 
text. Also 

note that the sendmail program runs setuid root. 


The way you can abuse this set of facts (if you have not yet guessed) is by spec 
ifying the 


=. 


file you wish read as the configuration file. Thus the command: 


sendmail -C/usr/accounts/random_joe/private/file 


Will give you a copy of random joe's private file. 


Another similar trick is to symlink your .mailcf file to joe's file and mail som 
eone. When mail 

executes sendmail (to send the mail), it will load in your mailcf and barf out j 
oe's stuff. 


First, link joe's file to your .mailcf . 


ln -s /usr/accounts/random_joe/private/file SHOME/.mailcf 


Next, send mail to someone. 


mail C488869@umcvmb.missouri.edu 
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"Until a few years ago maybe ten it was very common to 


see TWX and Telex machines in almost every business place." 


There were only minor differences between Telex and TWX. The biggest difference 
nat the former was always run by Western Union, while the latter was run by the 
cote for a number of years. TWX literally meant "(T)ype(W) riter e(x)change," a 
oe answer to competition from Western Union. There were "three row" and 
" 

e ee meaning the number of keys on the keyboard and how they were laid 
eee row" machines were simply part of the regular phone network; that is, 
bare dial out and talk to another TWX also connected on regular phone lines. 


Eventually these were phased out in favor of "newer and more improved" machines 
with 

additional keys, as well as a paper tape reader attachment which allowed sending 
the same 


message repeatedly to many different machines. These "four row" machines were no 
t on the 

regular phone network, but were assigned their own area codes (410-510-610-710-8 
10-910) 

where they still remain today. The only way a four row machine could call a thre 
e row 

machine or vice-versa was through a gateway of sorts which translated some of th 
e 

character set unique to each machine. 


Western Union's network was called Telex and in addition to being able to contac 
t (by dial 
up) other similar machines, Telex could connect with TWX (and vice-versa) as wel 
l as all the 
Western Union public offices around the country. Until the late 1950's or early 
1960's, 
every small town in America had a Western Union office. Big cities like Chicago 
had perhaps 

a dozen of them, and they used messengers to hand deliver telegrams around town. 


Telegrams could be placed in person at any public office, or could be called in 
to the nearest 
public office. 


By arrangement with most telcos, the Western Union office in town nearly always 

had the 

phone number 4321, later supplemented in automated exchanges with some prefix XX 

X- 
4321. Telegrams could be charged to your home phone bill (this is still the case 
in some 


communities) and from a coin phone, one did not ask for 4321, but rather, called 
the 
operator and asked for Western Union. This was necessary since once the telegram 
had 
been given verbally to the wire clerk, s/he in turn had to flash the hook and ge 
t your 
operator back on the line to tell them "collect five dollars and twenty cents" o 
r whatever 

the cost was. Telegrams, like phone calls, could be sent collect or billed third 
party. If you 

had an account with Western Union, i.e. a Telex machine in your office, you coul 
d charge the 

calls there, but most likely you would simply send the telegram from there in th 
e first place. 


Sometime in the early 1960's, Western Union filed suit against AT&T asking that 
they turn 
over their TWX business to them. They cited an earlier court ruling, circa 1950' 
s, which 
said AT&T was prohibited from acquiring any more telephone operating companies e 
xcept 
under certain conditions. The Supreme Court agreed with Western Union that "spok 
en 
messages" were the domain of Ma Bell, but "written messages" were the domain of 
Western 
Union. So Bell was required to divest itself of the TWX network, and Western Uni 
on has 
operated it since, although a few years ago they began phasing out the phrase ™ 
j X " in 
favor of "Telex II"; their original device being "Telex I" of course. TWX still 
uses ten digit 
dialing with 610 (Canada) or 710/910 (USA) being the leading three digits. Appar 
ently 410- 
510 have been abandoned; or at least they are used very little, and Bellcore has 
assigned 
510 to the San Francisco area starting in a year or so. 410 still has some funny 
things on it, 
like the Western Union "Infomaster," which is a computer that functions like a g 
ateway 
between Telex, TWX, EasyLink and some other stuff. 


Today, the Western Union network is but a skeleton of its former self. Now most 

of their 

messages are handled on dial up terminals connected to the public phone network. 
It has 

been estimated the TWX/Telex business is about fifty percent of what it was a de 

cade 

ago, if that much. 


Then there was the Time Service, a neat thing which Western Union offered for ov 
er 
seventy years, until it was discontinued in the middle 1960's. The Time Service 
provided an 


important function in the days before alternating current was commonly available 
. For 

example, Chicago didn't have AC electricity until about 1945. Prior to that we u 
sed DC, or 

direct current. 


Well, to run an electric clock, you need 60 cycles AC current for obvious reason 
Ss, SO prior to 

the conversion from DC power to AC power, electric wall clocks such as you see i 
n every 
office were unheard of. How were people to tell the time of day accurately? Ente 
r the 

Western Union clock. 


The Western Union, or “telegraph clock" was a spring driven wind up clock, but w 
ith a 
difference. The clocks were "perpetually self-winding," manufactured by the Self 
-Winding 
Clock Company of New York City. They had large batteries inside them, known as " 
telephone 
cells" which had a life of about ten years each. A mechanical contrivance in the 
clock would 
rotate as the clock spring unwound, and once each hour would cause two metal cli 
ps to 
contact for about ten seconds, which would pass juice to the little motor in the 
clock which 
in turn re-wound the main spring. The principle was the same as the battery oper 
ated 
clocks we see today. The battery does not actually run the clock -- direct curre 
nt can't do 


that -- but it does power the tiny motor which re-winds the spring which actuall 
y drives the 
clock. 


The Western Union clocks came in various sizes and shapes, ranging from the smal 
lest dials 
hich were nine inches in diameter to the largest which were about eighteen inch 
s in 
iameter. Some had sweep second hands; others did not. Some had a little red lig 
t bulb 

n the front which would flash. The typical model was about sixteen inches, and 
as found in 

ffices, schools, transportation depots, radio station offices, and of course in 
the telegraph 

office itself. 


oz 0oO7 AO =z 


The one thing all the clocks had in common was their brown metal case and cream- 
colored 
face, with the insignia "Western Union" and their corporate logo in those days w 
hich was a 
bolt of electricity, sort of like a letter "Z" laying on its side. And in somewh 
at smaller print 
below, the words "Naval Observatory Time. 


The local clocks in an office or school or wherever were calibrated by a "master 
clock" 
(actually a sub-master) on the premises. Once an hour on the hour, the (sub) mas 
ter clock 
would drop a metal contact for just a half second, and send about nine volts DC 
up the line 
to all the local clocks. They in turn had a "tolerance" of about two minutes on 
both sides of 
the hour so that the current coming to them would yank the minute hand exactly u 
pright 
onto the twelve from either direction if the clock was fast or slow. 


The sub-master clocks in each building were in turn serviced by the master clock 
in town; 
usually this was the one in the telegraph office. Every hour on the half hour, t 
he master 

clock in the telegraph office would throw current to the sub-masters, yanking th 
em into 
synch as required. And as for the telegraph offices themselves, they were servic 
ed twice a 
day by -- you guessed it the Naval Observatory Master clock in Our Nation's C 
apitol, by 

the same routine. 


Someone there would press half a dozen buttons at the same time, using all avail 


able 

fingers; current would flow to every telegraph office and synch all the master c 
locks in 

every community. Western Union charged fifty cents per month for the service, an 
d tossed 

the clock in for free! Oh yes, there was an installation charge of about two dol 
lars when 

you first had service (i.e. a clock) installed. 


The clocks were installed and maintained by the "clockman," a technician from We 
stern 
Union who spent his day going around hanging new clocks, taking them out of serv 
ice, 

changing batteries every few years for each clock, etc. 


What a panic it was for them when "war time" (what we now call Daylight Savings 
Time) 
came around each year! Wally, the guy who serviced all the clocks in downtown Ch 
icago had 
to start on *Thursday* before the Sunday official changeover just to finish them 
all by 
*Tuesday* following. He would literally rush in an office, use his screwdriver t 
o open the 
case, twirl the hour hand around one hour forward in the spring, (or eleven hour 
s *forward* 
in the fall since the hands could not be moved backward beyond the twelve going 
counterclockwise), slam the case back on, screw it in, and move down the hall to 
the next 


clock and repeat the process. He could finish several dozen clocks per day, and 
usually the 
office assigned him a helper twice a year for these events. 


He said they never bothered to line the minute hand up just right, because it wo 
uld have 


taken too long, and "..... anyway, as long as we got it within a minute or so, it 
would synch 
itself the next time the master clock sent a signal..." Working fast, it took a 


minute to a 

minute and a half to open the case, twirl the minute hand, put the case back on, 
"stop and 

BS with the receptionist for a couple seconds" and move along. 


The master clock sent its signal over regular telco phone lines. Usually it woul 
d terminate in 

the main office of whatever place it was, and the (sub) master there would take 
over at 

that point. 


Wally said it was very important to do a professional job of hanging the clock t 
o begin with. 
It had to be level, and the pendulum had to be just right, otherwise the clock w 
ould gain or 

lose more time than could be accommodated in the hourly synching process. He sai 
d it was a 
very rare clock that actually was out by even a minute once an hour, let alone t 
he two 
minutes of tolerance built into the gear works. 


".,.Sometimes I would come to work on Monday morning, and find out in the office 
that the 

clock line had gone open Friday evening. So nobody all weekend got a signal. Usu 

ally I would 
go down a manhole and find it open someplace where one of the Bell guys messed i 
t up, or 

took it off and never put it back on. To find out where it was open, someone in 
the office 

would 'ring out' the line; I'd go around downtown following the loop as we had i 
t laid out, 

and keep listening on my headset for it. When I found the break or the open, I w 
ould tie it 

down again and the office would release the line; but then I had to go to all th 
e clocks 

*before* that point and restart them, since the constant current from the office 
during 

the search had usually caused them to stop." 


But he said, time and again, the clocks were usually so well mounted and hung th 


at "...it was 

rare we would find one so far out of synch that we had to adjust it manually. Us 
ually the 
first signal to make it through once I repaired the circuit would yank everyone 
in town to 

make up for whatever they lost or gained over the weekend..." 


In 1965, Western Union decided to discontinue the Time Service. In a nostalgic l 
etter to 

subscribers, they announced their decision to suspend operations at the end of t 

he current 

month, but said "for old time's sake" anyone who had a clock was welcome to keep 
it and 

continue using it; there just would not be any setting signals from the master c 

locks any 

longer. 


Within a day or two of the official announcement, every Western Union clock in t 
he Chicago 

area headquarters building was gone. The executives snatched them off the wall, 
and took 

them home for the day when they would have historical value. All the clocks in t 
he telegraph 

offices disappeared about the same time, to be replaced with standard office-sty 
le electric 

wall clocks. 
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Tymnet and Telenet. Navigation around these networks is very simple, and usually 


explained in their on-line documentation. Furthermore, some systems will actuall 
y te you 

what is connected and how to get to it. In the case of Tymnet, after dialing in, 
at the log in 

prompt, type "information" for the on-line documentation. 


Accessing systems through networks is as simple as providing an address for it t 
o connect 

to. The best way to learn about the addresses and how to do things on a network 
is to read 

"A Novice's Guide to Hacking (1989 Edition)" which was in Issue 22, File 4 of 12 
, Volume 

Two (December 23, 1988). Some points are reiterated here. 


Once on a network, you provide the NUA (network user address) of the system you 
wish to 
connect to. NUAs are strings of 15 digits, broken up in to 3 fields, the NETWORK 


ADDRESS, the AREA PREFIX, and the DNIC. Each field has 5 digits, and are left pa 
dded 
with 0's where necessary. 


The DNIC determines which network to take the address from. Tymnet, for example, 
is 
03106. 03110 is Telenet. 


The AREA PREFIX and NETWORK ADDRESS determine the connection point. By providing 


the address of the system that you wish to connect to, you will be accessing it 
through the 
net... as if you were calling it directly. Obviously, then, this provides one mo 
re level of 

security for access. By connecting to an outdial, you can increase again the lev 
el of security 

you enjoy, by using the outdial in that area to connect to the remote system. 


Addendum - Accessing Tymnet Over Local Packet Networks 


This is just another way to get that extra step and/or bypass other routes. This 


table is 

copied from Tymnet's on-line information. As said earlier, it's a great resource 
, this on-line 

information! 


BELL ATLANTIC 


NODECITYSTATESPEEDACCESS 
NUMBERNETWORK0 352 6DOVERDELAWARE300/2400302/734- 
9465@PDN03526GEORGETOWNDELAWARE300/2400302/856- 
7055@PDN03526NEWARKDELAWARE300/2400302/366- 
0800@PDN03526WILMINGTONDELAWARE300/1200302/428- 
0030@PDN03526WILMINGTONDELAWARE2 400302/655- 
1144@PDNO6254WASHINGTONDIST. OF COL.300/1200202/479- 
7214@PDN06254WASHINGTON (MIDTOWN) DIST. OF COL.2400202/785- 
1688@PDN06254WASHINGTON (DOWNTOWN) DIST. OF COL.300/1200202/393- 

D GTO 

D GTO 

D GTO 


6003@P TON (MIDTOWN) DIST. OF COL.300/1200202/293- 
4641@P [TONDIST. OF COL.300/1200202/546- 
5549@P [TONDIST. OF COL.300/1200202/328- 


N06254WASHIN 
N06254WASHIN 
N06254WASHIN 


0619@PDN06254BETHESDAMARYLAND300/1200301/986- 
9942@PDN06254COLESVILLEMARYLAND300/2400301/989- 
9324@PDN06254HYATTSVILLEMARYLAND300/1200301/779- 
D 
D 


9935@PDN06254LAURELMARYLAND300/2400301/490- 
9971@PDNO6254ROCKVILLEMARYLAND300/1200301/340-9903@PDN06254SILVER 
SPRINGMARYLAND300/1200301/495-9911@PDN07771BERNARDSVILLENEW 
JERSEY300/2400201/766-7138@PDNO7771CLINTONNEW JERSEY300-1200201/730- 
8693@PDNO7771DOVERNEW JERSEY300/2400201/361- 
9211@PDNO7771EATONTOWN/RED BANKNEW JERSEY300/2400201/758- 

D 

D 

D 


8000@PDNO7771ELIZABETHNEW JERSEY300/2400201/289- 
5100@PDNO7771ENGLEWOODNEW JERSEY300/2400201/871- 
3000@PDNO7771FREEHOLDNEW JERSEY300/2400201/780- 
8890@PDNO7771HACKENSACKNEW JERSEY300/2400201/343-9200@PDNO7771JERSEY 
CITYNEW JERSEY300/2400201/659-3800@PDN07771LIVINGSTONNEW 

JERSEY 300/2400201/533-0561@PDNO7771LONG BRANCH/RED BANKNEW 

JERSEY 300/2400201/758-8000@PDNO7771MADISONNEW JERSEY300/2400201/593- 
0004@PDNO7771METUCHENNEW JERSEY300/2400201/906- 
9500@PDNO7771MIDDLETOWNNEW JERSEY300/2400201/957- 
9000@PDNO7771MORRISTOWNNEW JERSEY300/2400201/455- 
0437@PDNO7771NEWARKNEW JERSEY300/2400201/623-0083@PDNO7771NEW 
BRUNSWICKNEW JERSEY300/2400201/247-2700@PDNO7771NEW FOUNDLANDNEW 
JERSEY 300/2400201/697-9380@PDNO7771PASSAICNEW JERSEY300/2400201/473- 
6200@PDNO7771PATERSONNEW JERSEY300/2400201/345- 
7700@PDNO7771PHILLIPSBURGNEW JERSEY300/2400201/454- 
9270@PDNO7771POMPTON LAKESNEW JERSEY300/2400201/835-8400@PDNO7771RED 
BANKNEW JERSEY300/2400201/758-8000@PDNO7771RIDGEWOODNEW 
JERSEY300/2400201/445-4800@PDNO7771SOMERVILLENEW 
JERSEY 300/2400201/218-1200@PDNO7771SOUTH RIVERNEI 
JERSEY300/2400201/390-9100@PDNO7771SPRING LAKENE\ 
JERSEY300/2400201/974-0850@PDNO7771TOMS RIVERNEW 


OOWHUU YU 


ERSEY300/2400201/286-3800@PDNO777 1WASHINGTONNEW 
ERSEY300/2400201/689-6894@PDNO7771WAYNE/PATERSONNEW 
JERSEY300/2400201/345- 
7700@PDN03526ALLENTOWNPENNSYLVANIA300/1200215/435- 
0266@PDN11301ALTOONAPENNSYLVANIA300/1200814/946- 
8639@PDN11301ALTOONAPENNSYLVANIA2400814/949- 
0505@PDN03526AMBLERPENNSYLVANIA300/1200215/283- 
2170@PDN10672AMBRIDGEPENNSYLVANIA300/1200412/266- 
9610@PDN10672CARNEGIEPENNSYLVANIA300/1200412/276- 
1882@PDN10672CHARLEROIPENNSYLVANIA300/1200412/483- 
9100@PDNO3526CHESTER HEIGHTSPENNSYLVANIA300/1200215/358- 
0820@PDN03526COATESVILLEPENNSYLVANIA300/1200215/383- 
7212@PDN10672CONNELLSVILLEPENNSYLVANIA300/1200412/628- 
7560@PDN03526DOWNINGTON/COATES . PENNSYLVANIA300/1200215/383- 
7212@PDN03562DOYLESTOWNPENNS Y LVANIA300/1200215/340- 
0052@PDN03562GERMANTOWNPENNSYLVANIA300/1200215-843- 


D 
D 
D 
D 
D 
D 
D 
D 
D 
D 
D 
D 


4075@PDN10672GLENSHAWPENNSYLVANIA300/1200412/487- 
6868@PDN10672GREENSBURGPENNSYLVANIA300/1200412/836- 
7840@PDN11301HARRISBURGPENNSYLVANIA300/1200717/236- 
3274@PDN11301HARRISBURGPENNSYLVANIA2400717/238- 
0450@PDN10672INDIANAPENNSYLVANIA300/1200412/465-7210@PDN03526KING OF 
PRUSSIAPENNSYLVANIA300/1200215/270- 
2970@PDNO3526KIRKLYNPENNSYLVANIA300/1200215/789- 
5650@PDN03526LANSDOWNEPENNSYLVANIA300/1200215/626- 
9001@PDN10672LATROBEPENNSYLVANIA300/1200412/537- 
0340@PDN11301LEMOYNE/HARRISBURGPENNSYLVANIA300/1200717/236- 
3274@PDN10672MCKEESPORTPENNSYLVANIA300/1200412/673-6200@PDN10672NEW 
CASTLEPENNSYLVANIA300/1200412/658-5982@PDN10672NEW 
KENSINGTONPENNSYLVANTIA300/1200412/337- 
0510@PDN03526NORRISTOWNPENNSYLVANIA300/1200215/270- 
2970@PDN03526PAOLIPENNSYLVANIA300/1200215/648- 
0010@PDN03562PHILADELPHIAPENNSYLVANIA300/1200215/923- 
7792@PDN03562PHILADELPHIAPENNSYLVANTA300/1200215/557- 
0659@PDN03562PHILADELPHIAPENNSYLVANIA300/1200215/545- 
788 6@PDN03562PHILADELPHIAPENNSYLVANTA300/1200215/677- 
0321@PDN03562PHILADELPHIAPENNSYLVANTA2400215/625- 
0770@PDN10672PITTSBURGHPENNSYLVANIA300/1200412/281- 
8950@PDN10672PITTSBURGHPENNSYLVANIA300/1200412-687- 
4131@PDN10672PITTSBURGHPENNSYLVANIA2400412/261- 
9732@PDN10672POTTSTOWNPENNSYLVANIA300/1200215/327- 
8032@PDN03526QUAKERTOWNPENNSYLVANIA300/1200215/538- 
7032@PDN03526READINGPENNSYLVANIA300/1200215/375- 
7570@PDN10672ROCHESTERPENNSYLVANTA300/1200412/728- 
9770@PDNO3526SCRANTONPENNSYLVANIA300/1200717/348- 
1123@PDN03526SCRANTONPENNSYLVANIA2400717/341- 
1860@PDN10672SHARONPENNSYLVANIA300/1200412/342- 
1681@PDN03526TULLYTOWNPENNSYLVANIA300/1200215/547- 
3300@PDN10672UNIONTOWNPENNSYLVANIA300/1200412/437- 
5640@PDNO3562VALLEY FORGEPENNSYLVANIA300/1200215/270- 
2970@PDN10672WASHINGTONPENNSYLVANIA300/1200412/223- 
90 90@PDN03526WAYNEPENNSYLVANIA300/1200215/341- 

9605@PDN10672WI LKINSBURGPENNSYLVANIA300/1200412/241- 
100 6@PDN06254ALEXANDRIAVIRGINIA300/1200703/683- 
6710@PDN06254ARLINGTONVIRGINIA300/1200703/524- 
8961@PDN06254FAIRFAXVIRGINIA300/1200703/385- 
1343@PDN06254MCLEANVIRGINIA300/1200703/848-2941@PDN@PDN BELL 
ATLANTIC - NETWORK NAME IS PUBLIC DATA NETWORK (PDN) 


OOUVUUUVUUVOUVUUUUPUUVUUUVUUUUCUUUU UCU E 


(CONNECT MESSAGE) 


< uC. ER > (SYNCHRONIZES DATA SPEEDS) 


WELCOME TO THE BPA/DST PDN 


We LLR (TYMNET ADDRESS) 


131069 (ADDRESS CONFIRMATION - TYMNET DNIC) 


COM (CONFIRMATION OF CALL SET-UP) 


-GWY 0XXXX- TYMNET: PLEASE LOG IN: (HOST # WITHIN DASHES) 


BELL SOUTH 


NODECITYSTATEDENSITYACCESS 
NUMBERMODEM10207ATLANTAGEORGIA300/1200404/261- 
4633QPLSK10207ATHENSGEORGIA300/1200404/354- 
0614@PLSK10207COLUMBUSGEORGIA300/1200404/324- 
5771@PLSK10207ROMEGEORGIA300/1200404/234/7542@PLSK@PLSK BELLSOUTH - 
NETWORK NAME IS PULSELINK 


(CONNECT MESSAGE) 


s< CR > (SYNCHRONIZES DATA SPEEDS) 


(DOES NOT ECHO TO THE TERMINAL) 
CONNECTED 


PULSELINK 


Le es Soli ANS (TYMNET ADDRESS) 


(DOES NOT ECHO TO THE TERMINAL) 


PULSELINK: CALL CONNECTED TO 1 3106 


-GWY OXXXX- TYMNET: PLEASE LOG IN: (HOST # WITHIN DASHES) 


PACIFIC BELL 


NODECITYSTATEDENSITYACCESS 

NUMBERNETWORK0330 6BERKELEYCALIFORNIA300/1200415-548-2121@PPS06272EL 
SEGUNDOCALIFORNIA300/1200213-640- 
8548@PPS06272FULLERTONCALIFORNIA300/1200714-441- 

2777@PPS06272 INGLEWOODCALIFORNIA300/1200213-216- 
7667@PPS06272ANGELES (DOWNTOWN) CALIFORNIA300/1200213-687- 
3727@PPS06272LOS ANGELESCALIFORNIA300/1200213-480- 
1677@PPSO3306MOUNTAIN VIEWCALIFORNIA300/1200415-960- 
3363@PPS033060AKLANDCALIFORNIA300/1200415-893-9889@PPS03306PALO 
ALTOCALIFORNIA300/1200415-325- 


4666@PPS06272PASADENACALIFORNIA300/1200818-356-0780@PPS03306SAN 
FRANC ISCOCALIFORNIA300/1200415-543-8275@PPS03306SAN 

FRANC ISCOCALIFORNIA300/1200415-626-5380@PPS03306SAN 

FRANC ISCOCALIFORNIA300/1200415-362-2280@PPS03306SAN 
JOSECALIFORNIA300/1200408-920-0888@PPS06272SANTA 
ANNACALIFORNIA300/1200714-972-9844@PPS06272VAN 
NUYSCALIFORNIA300/1200818-780-1066@PPS@PPS PACIFIC BELL - NETWORK 
NAME IS PUBLIC PACKET SWITCHING (PPS) 


(CONNECT MESSAGE) 


< C R (SYNCHRONIZES DATA SPEEDS) 


(DOES NOT ECHO TO THE TERMINAL) 


ONLINE 1200 
WELCOME TO PPS: 415-XXX-XXXX 


T azat 26. = 9 (TYMNET ADDRESS) 


(DOES NOT ECHO UNTIL TYMNET RESPONDS) 


-GWY OXXXX- TYMNET: PLEASE LOG IN: (HOST # WITHIN DASHES) 


SOUTHERN NEW ENGLAND 

NODECITYSTATEDENSITYACCESS 

NUMBERSNETWORK0272 7BRIDGEPORTCONNECTICUT300/2400203/366- 
6972@CONNNET02727BRISTOLCONNECTICUT300/2400203/589- 
5100@CONNNET02727CANAANCONNECTICUT300/2400203/824- 
5103@CONNNET02727CLINTONCONNECTICUT300/2400203/669- 
4243@CONNNET02727DANBURYCONNECTICUT300/2400203/743- 
2906@CONNNET02727DANIELSONCONNECTICUT300/2400203/779- 
1880@CONNNET02727HARTFORD /MIDDLETOWNCONNECTICUT300/2400203/724- 
6219@CONNNET0272 7MERIDENCONNECTICUT300/2400203/237- 
3460@CONNNETO2727NEW HAVENCONNECTICUT300/2400203/776- 
1142@CONNNET02727NEW LONDONCONNECTICUT300/2400203/443- 
0884@CONNNETO2727NEW MILFORDCONNECTICUT300/2400203/355- 
0764@CONNNET02727NORWALKCONNECTICUT300/2400203/866- 
5305@CONNNETO027270LD GREDDWICHCONNNETICUT300/2400203/637- 
8872@CONNNETO027270LD SAYBROOKCONNECTICUT300/2400203/388- 
0778@CONNNETO02727SEYMOURCONNECTICUT300/2400203/881- 
1455@CONNNET02727STAMFORDCONNECTICUT300/2400203/324- 
9701@CONNNET02727STORRSCONNECTICUT300/2400203/429- 
4243@CONNNET02727TORRINGTONCONNECTICUT300/2400203/482- 
984 9@CONNNET02727WATERBURYCONNECTICUT300/2400203/597- 


0064@CONNNET02727WI LLIMANT ICCONNECTICUT300/2400203/456- 
4552@CONNNET0272 7WINDSORCONNECTICUT300/2400203/688- 
9330@CONNNETO2727WINDSOR LCKS/ENFIELDCONNECTICUT300/2400203/623- 


9804@CONNNET@CONNNET - SOUTHERN NEW ENGLAND TELEPHONE - NETWORK 


NAME IN CONNNET 


(CONNECT MESSAGE) 


H_ H_ <_ C_ R_> (SYNCHRONIZES DATA SPEEDS) 


(DOES NOT ECHO TO THE TERMINAL) 


CONNNET 


T_ <_ C_ R> (MUST BE CAPITAL LETTERS) 


26-SEP-88 18:33 (DATA) 
031069 (ADDRESS CONFIRMATION) 


COM (CONFIRMATION OF CALL SET-UP) 


-GWY OXXXX-TYMNET: PLEASE LOG IN: 


SOUTHWESTERN BELL 


NODECITYSTATEDENSITYACCESS NUMBERSNETWORK05443KANSAS 
CITYKANSAS300/1200316/225-9951@MRLK05443HAYSKANSAS300/1200913/625- 
8100@MRLK05443HUTCHINSONKANSAS 300/1200316/669- 

1052@MRLK0544 3LAWRENCEKANSAS 300/1200913/841- 

5580@MRLK0544 3MANHATTANKANSAS 300/1200913/539- 
9291@MRLK05443PARSONSKANSAS300/1200316/421- 


0620@MRLK05443SALINAKANSAS300/1200913/825- 
4547@MRLK05443TOPEKAKANSAS 300/1200913/235- 


1909@MRLK0 544 3WICHITAKANSAS300/1200316/269- 
1996@MRLK04766BRIDGETON/ST. LOUISMISSOURI300/1200314/622- 
O900@MRLK04766ST. LOUISMISSOURI300/1200314/622-0900@MRLK 


On a side note, the recent book The Cuckoo's Egg provides some interest 


mation (in 


the form of a story, however) on a Tymnet hacker. Remember that he was 


things, 


and hence he was cracked down upon. If you keep a low profile, networks 


rovide a 
good access method. 


If you can find a system that is connected to the Internet that you can 


rom 


ing infor 


into BIG 


should p 


get on f 


Tymnet, you are doing well. 
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INTRODUCTION 


DECWRL is a mail gateway computer operated by Digital's Western Research Laborat 
ory in 

Palo Alto, California. Its purpose is to support the interchange of electronic m 
ail between 

Digital and the "outside world." 


DECWRL is connected to Digital's Easynet, and also to a number of different outs 
ide 
electronic mail networks. Digital users can send outside mail by sending to 


DECWRL::"outside-address", and digital users can also receive mail by having you 
r 

correspondents route it through DECWRL. The details of incoming mail are more co 
mplex, 

and are discussed below. 


It is vitally important that Digital employees be good citizens of the networks 
to which we 

are connected. They depend on the integrity of our user community to ensure that 
tighter 
controls over the use of the gateway are not required. The most important rule i 
s "no chain 

letters," but there are other rules depending on whether the connected network t 
hat you 
are using is commercial or non-commercial. 


The current traffic volume (September 1989) is about 10,000 mail messages per da 
y and 

about 3,000 USENET messages per day. Gatewayed mail traffic has doubled every ye 
ar 

since 1983. DECWRL is currently a Vax 8530 computer with 48 megabytes of main me 
mory, 

2500 megabytes of disk space, 8 9600-baud (Telebit) modem ports, and various net 
work 

connections. They will shortly be upgrading to a Vax 8650 system. They run Ultri 
x 3.0 as 

the base operating system. 


ADMINISTRATION 


The gateway has engineering staff, but no administrative or clerical staff. They 
work hard 
to keep it running, but they do not have the resources to answer telephone queri 
es or 

provide tutorials in its use. 


They post periodic status reports to the USENET newsgroup dec.general. Various h 
elpful 

people usually copy these reports to the VAXNOTES "gateways" conference within a 
day or 

two. 


HOW TO SEND MAIL 


DECWRL is connected to quite a number of different mail networks. If you were 


logged on directly to it, you could type addresses directly, e.g. 


To: strange! foreign!address. 


But since you are not logged on directly to the gateway, you must send mail so t 
hat when it 
arrives at the gateway, it will be sent as if that address had been typed locall 


Y. 


* Sending from VMS 


If you are a VMS user, you should use NMAIL, because VMS mail does not know how 
to 

requeue and retry mail when the network is congested or disconnected. From VMS, 
address 

your mail like this: 


To: nm%DECWRL: :"strange!foreign!address" 


The quote characters (") are important, to make sure that VMS doesn't try to int 


erpret 
strange!foreign!address itself. If you are typing such an address inside a mail 


program, it 


will 


work as advertised. If you are using DCL and typing directly to the command 


ine, you 


should beware that DCL likes to remove quotes, so you will have to enclose the e 
ntire 

address in quotes, and then put two quotes in every place that one quote should 
appear in 

the address: 


$ mail test.msg "nm%DECWRL::""foreign!addr""" /subj="hello" 


Note 


the three quotes in a row after foreign!addr. The first two of them are dou 


bled 


to 


produce a single quote in the address, and the third ends the address itself (ba 
lancing the 
quote in front of the nm%). 


Here 


are some typical outgoing mail addresses as used from a VMS system: 


: nmSDECWRL: :"111-winkin!netsys!phrack" 


: nmSDECWRL: :"postmaster@msp.pnet.sc.edu" 
: nmSDECWRL::"netsys!phrack@uunet.uu.net" 


: nmsDECWRL: :"phrackserv@CUNYVM.bitnet" 


: nmSDECWRL: :"Chris.Jones@f654.n987.z1.fidonet.org" 


* Sending from Ultrix 


ust 


£. 


C al 
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j 
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If your Ultrix system has been configured for it, then you can, from your Ultrix 
system, 


send directly to the foreign address, and the mail software will take care 
ll of the 


for you. Most Ultrix systems in Corporate Research and in the Pa 
Lto 


luster are configured this way. 


To find out whether your Ultrix system has been so configured, just try it and s 


ee what 
happens. If it doesn't work, you will receive notification almost instantly. 


NOTE: The Ultrix mail system is extremely flexible; it is almost completely conf 
igurable by 
the customer. While this is valuable to customers, it makes it very difficult to 
write global 

instructions for the use of Ultrix mailers, because it is possible that the loca 
L changes have 
produced something quite unlike the vendor-delivered mailer. One of the popular 
changes is 
to tinker with the meaning of quote characters (") in Ultrix addresses. Some sys 
tems 

consider that these two addresses are the same: 


sitel!site2!user@host.dec.com 


and 


"sitel!site2!user"@host.dec.com 


while others are configured so that one form will work and the other will not. A 
ll of these 

examples use the quotes. If you have trouble getting the examples to work, pleas 
e try 

them again without the quotes. Perhaps your Ultrix system is interpreting the qu 
otes 

differently. 


If your Ultrix system has an IP link to Palo Alto (type "/etc/ping decwrl.dec.co 
m" to find 

out if it does), then you can route your mail to the gateway via IP. This has th 
e advantage 

that your Ultrix mail headers will reach the gateway directly, instead of being 
translated 
into DECNET mail headers and then back into Ultrix at the other end. Do this as 
follows: 


To: "alien!address"@decwrl.dec.com 


The quotes are necessary only if the alien address contains a ! character, but t 
hey don't 

hurt if you use them unnecessarily. If the alien address contains an "@" charact 
er, you will 

need to change it into a "%" character. For example, to send via IP to joe@widge 
t.org, you 

should address the mail. 


To: "joeswidget.org"@decwrl.dec.com 


If your Ultrix system has only a DECNET link to Palo Alto, then you should addre 
ss mail in 

much the same way that VMS users do, save that you should not put the nm% in fro 
nt of 

the address: 


To: DECWRL::"strange! foreign! address" 


Here are some typical outgoing mail addresses as used from an Ultrix system that 
has IP 

access. Ultrix systems without IP access should use the same syntax as VMS users 
, except 
that the nm% at the front of the address should not be used. 


To: "lll-winken!netsys!phrack"@decwrl.dec.com 


To: "postmaster%msp.pnet.sc.edu"@decwrl.dec.com 


To: "phrackservsCUNYVM.bitnet"@decwrl.dec.com 


To: "netsys!phrack%Suunet.uu.net"@decwrl.dec.com 


To: "Chris.Jones@f654.n987.z1.fidonet.org"@decwrl.dec.com 


DETAILS OF USING OTHER NETWORKS 


A of the world's computer networks are connected together, more or less, so it 
is hard to 

draw exact boundaries between them. Precisely where the internet ends and UUCP b 
egins is 

a matter of interpretation. 


For purposes of sending mail, though, it is convenient to divide the network uni 
verse into 
these categories: 


Easynet: 


Digital's internal DECNET network. Characterized by addresses of the form 
NODE: : USER. Easynet can be used for commercial purposes. 


Internet: 


A collection of networks including the old ARPAnet, the NSFnet, the CSnet, and 
others. Most international research, development, and educational organizations 
are 

connected in some fashion to the Internet. Characterized by addresses of the for 
m 

user@site.subdomain.domain. The internet itself cannot be used for commercial 
purposes. 


UUCP: 
A very primitive network with no management, built with auto-dialers phoning one 
computer from another. Characterized by addresses of the form placel!place2!user 


The UUCP network can be used for commercial purposes provided that none of the 
sites through which the message is routed objects to that. 


USENET: 


Not a network at all, but a layer of software built on top of UUCP and Internet. 


BITNET: 


An IBM-based network linking primarily educational sites. Digital users can send 
to 
BITNET as if it were part of internet, but BITNET users need special instruction 
Ss 

for reversing the process. BITNET cannot be used for commercial purposes. 


Fidonet: 


A network of personal computers. I am unsure of the status of using Fidonet for 
commercial purposes, nor am I sure of its efficacy. 


DOMAINS AND DOMAIN ADDRESSING 


There is a particular network called "the Internet;" it is somewhat related to w 
hat used to 
be "the ARPAnet." The Internet style of addressing is flexible enough that peopl 


e use it 

for addressing other networks as well, with the result that it is quite difficul 
t to look at an 

address and tell just what network it is likely to traverse. But the phrase "Int 
ernet 

address" does not mean "mail address of some computer on the Internet" but rathe 
r "mail 

address in the style used by the Internet." Terminology is even further confused 
because 

the word "address" means one thing to people who build networks and something en 
tirely 
different to people who use them. In this file an "address" is something like 
"mike@decwrl.dec.com" and not "192.1.24.177" (which is what network engineers wo 
uld call 

an "internet address"). 


The Internet naming scheme uses hierarchical domains, which despite their title 
are just a 

bookkeeping trick. It doesn't really matter whether you say NODE: :USER or 
USER@NODE, but what happens when you connect two companies' networks together an 
d 

they both have a node ANCHOR?? You must, somehow, specify which ANCHOR you mean. 


You could say ANCHOR.DEC::USER or DEC.ANCHOR::USER or USER@ANCHOR.DEC or 


USER@DEC.ANCHOR. The Internet convention is to say USER@ANCHOR.DEC, with the 
owner (DEC) after the name (ANCHOR). 


But there could be several different organizations named DEC. You could have Dig 
ital 
Equipment Corporation or Down East College or Disabled Education Committee. The 
technique that the Internet scheme uses to resolve conflicts like this is to hav 
e 
hierarchical domains. A normal domain isn't DEC or STANFORD, but DEC.COM (commer 
cial) 
and STANFORD.EDU (educational). These domains can be further divided into 
ZK3.DEC.COM or CS.STANFORD.EDU. This doesn't resolve conflicts completely, thoug 
h: 
both Central Michigan University and Carnegie-Mellon University could claim to b 
e 
CMU.EDU. The rule is that the owner of the EDU domain gets to decide, just as th 
e owner 

of the CMU.EDU gets to decide whether the Electrical Engineering department or t 
he 

Elementary Education department gets subdomain EE.CMU.EDU. 


The domain scheme, while not perfect, is completely extensible. If you have two 
addresses 

that can potentially conflict, you can suffix some domain to the end of them, th 
ereby 
making, say, decwrl.UUCP be somehow different from DECWRL.ENET. 


DECWRL's entire mail system is organized according to Internet domains, and in f 
act we 

handle all mail internally as if it were Internet mail. Incoming mail is convert 
ed into 
Internet mail, and then routed to the appropriate domain; if that domain require 
s some 

conversion, then the mail is converted to the requirements of the outbound domai 
nas it 

passes through the gateway. For example, they put Easynet mail into the domain E 
NE. 


On a side note, the recent book The Cuckoo's Egg provides some interesting infor 
mation (in 
the form of a story, however) on a Tymnet hacker. Remember that he was into BIG 
things, 

and hence he was cracked down upon. If you keep a low profile, networks should p 
rovide a 

good access method. 


If you can find a system that is connected to the Internet that you can get on f 
rom 
Tymnet, you are doing well. 


Username@f<node #>.n<net #>.z<zone #>.ifna.org 


In other words, if I wanted to mail to Silicon Swindler at 1:135/5, the address 
would be 

Silicon_Swindler@f5.n135.z1.ifna.org and, provided that your mailer knows the .i 
fna.org 
domain, it should get through alright. Apparently, as of the writing of this art 
icle, they have 

implemented a new gateway name called fidonet.org which should work in place of 
ifna.org in 

all routings. If your mailer does not know either of these domains, use the abov 
e routing but 

replace the first "@" with a "%S" and then afterwards, use either of the followin 
g mailers 
after the "@": CS.ORST.EDU or K9.CS.ORST.EDU (i.e. username%f<node #>.n<net 
#>.z<zone #>.fidonet.org@CS.ORST.EDU [or replace CS.ORST.EDU with 
K9.CS.ORST.EDU]). 


The following is a list compiled by Bill Fenner (WCF@PSUECL.BITNET) that was pos 
ted on 
INFONETS DIGEST which lists a number of FIDONET gateways: 


NetNodeNode 


Namel10456milehi.ifna.orgl0555casper.ifna.orgl07320rubbs.ifna.orgl109661blkcat.ifn 
a.org]25406fidogate.ifna.org12819hipshk.ifna.orgl2965insight.ifna.org143N/Afidog 
ate.ifna.org152200castle.ifna.org161N/Afidogate.ifna.org36917megasys.ifna.org 


NOTE: The UUCP equivalent node name is the first part of the node name. In other 


words, the UUCP node milehi is listed as milehi.ifna.org but can be mailed direc 


tly over the 
UUCP network. 


Another way to mail to FIDONET, specifically for Internet people, is in this for 


mat: 


ihnp4!necntc!ncoast!ohiont!<net #>!<node #>!user_name@husc6.harvard.edu 


And for those UUCP mailing people out there, just use the path described and ign 


ore the 
@huscd.harvard.edu portion. 
FIDONET bulletin board, but 


ONTYME 


There is a FIDONET NODELIST available on most any 
it is quite large. 


Previously known as Tymnet, OnTyme is the McDonnell Douglas revision. After they 


bought 


out Tymnet, they renamed the company and opened an experimental Internet gateway 


at 


ONTYME.TYMNET.COM but this is supposedly only good for certain corporate address 


es 


within McDonnell Douglas and Tymnet, not their customers. The userid format is x 


x.yyy or 


xx.y/yy where xx is a net name and yyy (or y/yy) is a true username. If you cann 


ot directly 
nail this, try: 


XX. VVy SONTYME. TYM 


130.Sodium Chlorate by the Jolly Roger 


Sodium Chlorate is a strong oxidizer used in the manufacture of explosives. It c 


an be used 


in place of Potassium Chlorate. 


Material Required: 


2 carbon or lead rods (1 in. diameter by 5 in. long) 

Salt, or ocean water 

Sulfuric acid, diluted 

Motor Vehicle 

Water 

2 wires, 16 gauge (3/64 in. diameter approx.), 6 ft. long, insulated. 
Gasoline 


1 gallon glass jar, wide mouth (5 in. diameter by 6 in. high approx.) 
Sticks 


String 


Teaspoon 


Trays 


Cup 

Heavy cloth 
Knife 
Large flat pan or tray 


Sources of Carbon or Lead rods: 


Dry Cell Batteries (2-« in. diameter by 7" long) or plumbing supply store. 


Sources of Salt Water: 


Grocery store or ocean 


Sources of Sulfuric Acid: 


Motor Vehicle Batteries. 


Procedure: 


Mix « cup of salt into the one gallon glass jar with 3 liters (3 quarts) of wate 
É; 


Add 2 teaspoons of battery acid to the solution and stir vigorously for 5 minute 
S. 


Strip about 4 inches of insulation from both ends of the two wires. 
With knife and sticks, shape 2 strips of wood 1 by 1/8 by 1-«. Tie the wood stri 
ps to the 


lead or carbon rods so that they are 1-« inches apart. 


Connect the rods to the battery in a motor vehicle with the insulated wire. 


Submerge 4-« inches of the rods in the salt water solution. 


With gear in neutral position, start the vehicle engine. Depress the accelerator 
approx. 1/5 
of its full travel. 


Run the engine with the accelerator in this position for 2 hours, then shut it d 
own for 2 
hours. 


Repeat this cycle for a total of 64 hours while maintaining the level of the aci 
d-salt water 
solution in the glass jar. 


CAUTION: This arrangement employs voltages which can be quite dangerous! 


Do not touch bare wire leads while engine is running!! 


Shut off the engine. Remove the rods from the glass jar and disconnect wire lead 
s from the 
battery. 


Filter the solution through the heavy cloth into a flat pan or tray, leaving the 
sediment at 
the bottom of the glass jar. 


Allow the water in the filtered solution to evaporate at room temperature (appro 
x. 16 
hours). The residue is approximately 60% or more sodium chlorate which is pure e 
nough 

to be used as an explosive ingredient. 


131.Mercury Fulminate by the Jolly Roger 


Mercury Fulminate is used as a primary explosive in the fabrication of detonator 
s. It is to 

be used with a booster explosive such as picric acid or RDX (which are elsewhere 
in this 

Cookbook). 


Material Required: 


Nitric Acid, 90% conc. (1.48 sp. gr) 
Mercury 

Ethyl (grain) alcohol (90%) 

iltering material [Paper Towels] 
Teaspoon measure (7, «, and 1 tsp. capacity)-aluminum, stainless steel or wax co 
ated 

Heat Source 

Clean wooden stick 

Clean water 

Glass containers 

Tape 

Syringe 


Hy 


Source of Nitric Acid: 


Elsewhere in this Cookbook 
Industrial metal processors 


Source of Mercury: 


Thermometers 
Mercury switches 
Old radio tubes 


Procedure: 


Dilute 5 teaspoons of nitric acid with 2-« teaspoons of clean water in a glass c 
ontainer by 
adding the acid to the water. 


Dissolve 1/8 teaspoon of mercury in the diluted nitric acid. This will yield dar 
k red fumes. 

NOTE: It may be necessary to add water, on drop at a time, to the mercury-acid 
solution in order to start a reaction. 


CAUTION: Acid will burn skin and destroy clothing. If any is spilled, wash it 
away with a large quantity of water. Do NOT inhale fumes! 


Warm 10 teaspoons of the alcohol in a container until the alcohol feels warm to 
the inside of 
the wrist. 


Pour the metal-acid solution into the warm alcohol. Reaction should start in les 
s than 5 
minutes. Dense white fumes will be given off during the reaction. As time lapses 
the 

jo È 

fumes will become less dense. Allow 10 to 15 minutes to complete reaction. Fulmi 
nate will 
settle to the bottom. 


CAUTION: This reaction generates large quantities of toxic, flammable fumes. 
The process MUST be conducted outdoors or in a well-ventilated area, away 
from sparks or open flames. DO NOT inhale fumes! 


Filter the solution through a paper towel into a container. Crystals may stick t 
o the side of 
the container. If so, tilt and squirt water down the sides of the container unti 
l all of the 
material collects on the filter paper. 


Wash the crystals with 6 teaspoons of ethyl alcohol. 


Allow these mercury fulminate crystals to air dry. 


CAUTION: Handle dry explosive with great care. Do not scrape or handle it 


roughly! Keep away from sparks or open flames. Store in a cool, dry place. 


132.Improvised Black Powder by The Jolly Roger 


Black powder can be prepared in a simple, safe manner. It may be used as blastin 


g or gun 
powder. 


Alcoho 


Materials: 


Wood charcoal] 
Sulfur, powdered, « cup 


5 p 


ints 


(2-« 


iters) 


esistant 


Cloth, 


T 


(metal, ceramic, etc.) 
Flat window screening, at least 1 foot 
Large wooden stick 


at least 2 feet 


Procedure: 


go] 


ace alcoho 


Water, 3 cups (3/4 liter) 
Heat source 


2 buckets - each 2 gallon (7-« liters) 


(60 cm) 


Potassium Nitrate, granulated, 3 cups (3/4 liter) 
L, powdered, 2 cups 


(whiskey, rubbing alcohol, etc.) 


square 


in one of the buckets. 


Place potassium nitrate, charcoal, and sul 
1 cup water 
and mix thoroughly with wooden stick unti 


capaci 


ty, at least one of which is heat r 


(30 cm) square 


all 


lfur in the heat resistant bucket. Add 


ingredients are dissolved. 


Add remaining water (2 cups) to mixture. Place bucket on heat source and stir un 


til small 


bubbles begin to form. 


CAUTION: DO NOT boil mixture. Be sure ALL mixture stays wet. If any is dry, 
as on sides of pan, it may ignite! 


Remove bucket from heat and pour mixture into alcohol while stirring vigorously. 


Let alcohol mixture stand about 5 minutes. Strain mixture through cloth to obtai 
n black 
powder. Discard liguid. Wrap cloth around black powder and squeeze to remove all 


excess liquid. 


Place screening over dry bucket. Place workable amount of damp powder on screen 
and 
granulate by rubbing solid through screen. NOTE: If granulated particles appear 
to 

stick together and change shape, recombine entire batch of powder and repeat ste 
ps 5 

& 6. 


Spread granulated black powder on flat, dry surface so that layer about « inch ( 
1-7 cm) is 

formed. Allow to dry. Use radiator, or direct sunlight. This should be dried as 
soon as 

possible, preferably in an hour. The longer the drying period, the less effectiv 
e the 

black powder. 


CAUTION: Remove from heat AS SOON AS granules are dry. Black powder is 
now ready to use. 


133.Nitric Acid by The Jolly Roger 


Nitric Acid is used in the preparation of many explosives, incendiary mixtures, 
and acid 
delay timers. It may be prepared by distilling a mixture of potassium nitrate an 
d 

concentrated sulfuric acid. 


Material Required: 


Potassium Nitrate (2 parts by volume) 

CONCENTRATED sulfuric acid (1 part by volume) 

2 bottles or ceramin jugs (narrow necks are preferable) 
Pot or frying pan 

Heat source (wood, charcoal, or coal) 

Tape (paper, electrical, masking, but NOT cellophane!) 
Paper or rags 


IMPORTANT: If sulfuric acid is obtained from a motor vehicle battery, concentrat 
e it by 
boiling it UNTIL white fumes appear. DO NOT INHALE FUMES. 


NOTE: The amount of nitric acid produced is the same as the amount of potassium 
nitrate. 

Thus, for two tablespoons of nitric acid, use 2 tablespoons of potassium nitrate 
and 1 

tablespoonful of concentrated sulfuric acid. 


Source of Potassium Nitrate: 


Elsewhere in this Cookbook 
Drug stores 


Source of CONCENTRATED sulfuric acid: 


Motor vehicle batteries 
Industrial plants 


Procedure: 


Place dry potassium nitrate in bottle or jug. Add sulfuric acid. Do not fill the 
bottle more 
than 7 full. Mix until paste is formed. 


CAUTION: DO NOT INHALE FUMES! 


Wrap paper or rags around necks of two bottles. securely tape necks of two bottl 
es 

together. Be sure that bottles are flush against each other and that there are n 
o air 

spaces. 


Support bottles on rocks or cans so that empty bottle is SLIGHTLY lower than bot 

tle 

containing paste so that nitric acid that is formed in receiving bottle will not 
run into 

other bottle. 


Build fire in pot or frying pan. 


Gently heat bottle containing mixture by gently moving fire in and out. As red f 
umes begin 
to appear periodically pour cool water over empty receiving bottle. Nitric acid 
will begin 

to form in receiving bottle. 


CAUTION: Do not overheat or wet bottle containing mixture or it may shatter. 
As an added precaution, place bottle to be heated in heat resistant container 
filled with sand or gravel. Heat this outer container to produce nitric acid. 


Continue the above process until no more red fumes are formed. If the nitric aci 
d formed in 

the receiving bottle is not clear (cloudy) pour it into cleaned bottle and repea 
t steps 2- 

6. 


CAUTION: Nitric acid should be kept away from all combustibles and should be 
kept in a SEALED CERAMIC OR GLASS container. DO NOT inhale fumes! 


134.Dust Bomb Instructions by The Jolly Roger 


An initiator which will initiate common material to produce dust explosions can 
be rapidly 
and easily constructed. This type of charge is ideal for the destruction of encl 


osed areas 
such as rooms or buildings. 


Material Required: 


A flat can, 3 in. (8 cm) in diameter and 1-« in. (3-3/4 cm) high. A 6-« ounce tu 


na can 

serves the purpose quite well. 

lasting cap 

xplosive 

luminum (may be wire, cut sheet, flattened can, or powder) 
arge nail, 4 in. (10 cm) long 

ooden rod - 7 in. (6 mm) diameter 

lour, gasoline, and powder or chipped aluminum 


Wen YS ww 


NOTE: Plastic explosive produce better explosions than cast explosives. 


Procedure: 


Using the nail, press a hole through the side of the tuna can 3/8 inch to « inch 
(1 to 1-« cm) 


from the bottom. Using a rotating and lever action, enlarge the hole until it wi 
ll 


accommodate the blasting cap. 


Place the wooden rod in the hole and position the end of the rod at the center o 
f the can. 


Press explosive into the can, being sure to surround the rod, until it is 3/4 in 
ch (2 cm) from 
the top of the can. Carefully remove the wooden rod. 


Place the aluminum metal on top of the explosive. 


Just before use, insert the blasting cap into the cavity made by the rod. The in 
itiator is 
now ready to use. 


NOTE: If it is desired to carry the initiator some distance, cardboard may 


be pressed on top of the aluminum to insure against loss of material. 


How to Use: 


This particular unit works quite well to initiate charges of five pounds of flou 
r, « gallon (1- 

2/3 liters) of gasoline, or two pounds of flake painters aluminum. The solid mat 
erials may 
merely be contained in sacks or cardboard cartons. The gasoline may be placed in 
plastic 
coated paper milk cartons, as well as plastic or glass bottles. The charges are 
placed 
directly on top of the initiator and the blasting cap is actuated electrically o 
r by a fuse 

depending on the type of cap employed. this will destroy a 2,000 cubic feet encl 
osure 

(building 10 x 20 x 10 feet). 


Note: For larger enclosures, use proportionally larger initiators and charges. 


135.Carbon-Tet Explosive by The Jolly Roger 


A moist explosive mixture can be made from fine aluminum powder combined with ca 
rbon 

tetrachloride or tetrachloroethylene. This explosive can be detonated with a bla 
sting cap. 


Material Required: 


Fine aluminum bronzing powder 

Carbon Tetrachloride or Tetrachloroethylene 
Stirring rod (wood) 

Mixing container (bowl, bucket, etc.) 


Measuring container (cup, tablespoon, etc.) 
Storage container (jar, can, etc.) 

Blasting cap 

Pipe, can or jar 


Source of Carbon Tetrachloride: 


Paint store 
Pharmacy 
Fire extinguisher fluid 


Source of Tetrachloroethylene: 


Dry cleaners 
Pharmacy 


Procedure: 


Measure out two parts aluminum powder to one part carbon tetrachloride or 
tetrachlorethylene liquid into mixing container, adding liquid to powder while s 
tirring 

with the wooden rod. 


Stir until the mixture becomes the consistency of honey syrup. 


